Vulnerabilities in zephyrproject

110 results
Vexday analysis

O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.

CVE-2026-11893MEDIUMDouble free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb)EPSS 0.2%CVE-2026-10645MEDIUMOut-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem imageEPSS 0.2%CVE-2026-13479LOWOut-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handlerEPSS 0.2%CVE-2026-10648MEDIUMNULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustionEPSS 0.2%CVE-2026-10670MEDIUMUser-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifierEPSS 0.2%CVE-2026-10667HIGHSMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threadsEPSS 0.1%CVE-2026-12631MEDIUMBroken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr kernelEPSS 0.1%CVE-2026-10677MEDIUMKernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource poolEPSS 0.1%CVE-2026-10674MEDIUMDoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabledEPSS 0.1%CVE-2026-10659MEDIUMNULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resumeEPSS 0.1%CVE-2026-10679LOWDivide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)EPSS 0.1%CVE-2026-8718HIGHOut-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLSEPSS 0.1%CVE-2026-12366HIGHUse-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposalEPSS 0.1%CVE-2026-12364HIGHMissing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of serviceEPSS 0.1%CVE-2026-10681MEDIUMSMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slotEPSS 0.1%CVE-2026-13478MEDIUMOut-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_countEPSS 0.1%CVE-2026-9771HIGHMissing device-pointer validation in flash_copy() syscall allows userspace privilege escalationEPSS 0.1%CVE-2026-11743MEDIUMMissing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and writeEPSS 0.1%CVE-2026-12634MEDIUMOut-of-bounds stack write in the settings NVS backend from over-reported nvs_read lengthEPSS 0.1%CVE-2026-12232MEDIUMOut-of-bounds read via unvalidated stream_id in Intel ALH DAI get_propertiesEPSS 0.1%