Vulnerabilidades en zephyrproject

110 resultados
Análisis Vexday

O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.

CVE-2026-13216MEDIUMOut-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability lengthEPSS 0.2%CVE-2026-10669HIGHXtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validationEPSS 0.2%CVE-2026-14697MEDIUMIPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of serviceEPSS 0.2%CVE-2026-12630MEDIUM6LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing modeEPSS 0.2%CVE-2026-10654LOWRFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth ClassicEPSS 0.2%CVE-2026-13213MEDIUMBluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_registerEPSS 0.2%CVE-2026-11894MEDIUMDouble-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error pathsEPSS 0.2%CVE-2026-12363MEDIUMOut-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0EPSS 0.2%CVE-2026-12051MEDIUMNULL pointer dereference in USB DFU device_next download handler (handle_download)EPSS 0.2%CVE-2026-13481MEDIUMOut-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTPEPSS 0.2%CVE-2026-12629MEDIUMPL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of serviceEPSS 0.2%CVE-2026-13480LOWOut-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handlerEPSS 0.2%CVE-2026-10643HIGHOut-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)EPSS 0.2%CVE-2026-10635MEDIUMDangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-initEPSS 0.2%CVE-2026-12519MEDIUMOut-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsingEPSS 0.2%CVE-2026-14366MEDIUMSiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pktEPSS 0.2%CVE-2026-10680HIGHOut-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflowEPSS 0.2%CVE-2026-10682MEDIUMOut-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspaceEPSS 0.2%CVE-2026-10671HIGHUser thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)EPSS 0.2%CVE-2026-12999MEDIUMInfineon Airoc Wi-Fi driver leaks TX buffers on send failure, leading to permanent pool exhaustionEPSS 0.2%