Vulnerabilidades em zephyrproject
110 resultadosAnálise Vexday
O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.
CVE-2026-10660MEDIUMShared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruptionEPSS 0.2%CVE-2026-10642MEDIUMUnbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow controlEPSS 0.2%CVE-2026-10663MEDIUMUse-after-free / double-free of the root USB device in the experimental USB host stackEPSS 0.2%CVE-2026-13343MEDIUMUninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responderEPSS 0.2%CVE-2026-10639MEDIUMUse-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`EPSS 0.2%CVE-2026-10668LOWHost-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driverEPSS 0.2%CVE-2026-14368MEDIUMOff-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parserEPSS 0.2%CVE-2026-10664MEDIUMOut-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)EPSS 0.2%CVE-2026-13212HIGHZephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring descriptor idEPSS 0.2%CVE-2026-10644MEDIUMOut-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte bufferEPSS 0.2%CVE-2026-7007MEDIUMDivision by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem imageEPSS 0.2%CVE-2026-10683LOWDesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)EPSS 0.2%CVE-2026-12522HIGHStack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fieldsEPSS 0.2%CVE-2026-12633HIGHOut-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router AdvertisementEPSS 0.2%CVE-2026-12520MEDIUMStack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlersEPSS 0.2%CVE-2026-10647MEDIUMDeadlock denial of service in USB CDC-NCM device class on TX enqueue failureEPSS 0.2%CVE-2026-14696MEDIUMEthernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustionEPSS 0.2%CVE-2026-12052MEDIUMOut-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the responseEPSS 0.2%CVE-2026-2411MEDIUMBluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic valuesEPSS 0.2%CVE-2026-13215MEDIUMZephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a crafted filesystem imageEPSS 0.2%