CVEs we hold for Zephyrproject
Records whose assigning authority named Zephyrproject as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9771Missing device-pointer validation in flash_copy() syscall allows userspace privilege escalationzephyrproject zephyr
CVE-2026-9728TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memoryzephyrproject zephyr
CVE-2026-9263Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packetszephyrproject zephyr
CVE-2026-8718Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLSzephyrproject zephyr
CVE-2026-8023Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file…zephyrproject zephyr
CVE-2026-7656Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stackzephyrproject zephyr
CVE-2026-7007Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem imagezephyrproject zephyr
CVE-2026-5590net: ip/tcp: Null pointer dereference can be triggered by a race conditionzephyrproject-rtos Zephyr
CVE-2026-5589Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.zephyrproject-rtos Zephyr
CVE-2026-5068bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_datazephyrproject-rtos Zephyr
CVE-2026-5067Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Keyzephyrproject-rtos Zephyr
CVE-2026-5066net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect functionzephyrproject-rtos Zephyr
CVE-2026-2411Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication…zephyrproject zephyr
CVE-2026-16515ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification…zephyrproject zephyr
CVE-2026-16514Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemovedzephyrproject zephyr
CVE-2026-16512Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frameszephyrproject zephyr
CVE-2026-16148Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy delayable work itemzephyrproject zephyr
CVE-2026-16147it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruptionzephyrproject zephyr
CVE-2026-15924Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr socketszephyrproject zephyr
CVE-2026-15923Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_sizezephyrproject zephyr
CVE-2026-15893Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoSzephyrproject zephyr
CVE-2026-15892Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of servicezephyrproject zephyr
CVE-2026-15891NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gatewayzephyrproject zephyr
CVE-2026-15461Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS inputzephyrproject zephyr
CVE-2026-15460Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive pathzephyrproject zephyr
CVE-2026-14986Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transactionzephyrproject zephyr
CVE-2026-14697IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of servicezephyrproject zephyr
CVE-2026-14696Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustionzephyrproject zephyr
CVE-2026-14368Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parserzephyrproject zephyr
CVE-2026-14367I3C IBI work-node free-list data race between ISR and workqueue threadzephyrproject zephyr
CVE-2026-14366SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pktzephyrproject zephyr
CVE-2026-13735WireGuard keepalive transport-data messages accepted without Poly1305 authenticationzephyrproject zephyr
CVE-2026-13734Zephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay endpoint hijackzephyrproject zephyr
CVE-2026-13481Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTPzephyrproject zephyr
CVE-2026-13480Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handlerzephyrproject zephyr
CVE-2026-13479Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handlerzephyrproject zephyr
CVE-2026-13478Out-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_countzephyrproject zephyr
CVE-2026-13351net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packetszephyrproject-rtos Zephyr
CVE-2026-13343Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responderzephyrproject zephyr
CVE-2026-13217NULL-pointer dereference in Zephyr OCPP CALLRESULT parsing via unchecked strtok_r/atoizephyrproject zephyr
CVE-2026-13216Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability lengthzephyrproject zephyr
CVE-2026-13215Zephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a crafted filesystem imagezephyrproject zephyr
CVE-2026-13213Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_registerzephyrproject zephyr
CVE-2026-13212Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring descriptor idzephyrproject zephyr
CVE-2026-12999Infineon Airoc Wi-Fi driver leaks TX buffers on send failure, leading to permanent pool exhaustionzephyrproject zephyr
CVE-2026-12634Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read lengthzephyrproject zephyr
CVE-2026-12633Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router Advertisementzephyrproject zephyr
CVE-2026-12632Out-of-bounds read in Zephyr PTP message parsing from unvalidated message typezephyrproject zephyr
CVE-2026-12631Broken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr kernelzephyrproject zephyr
CVE-2026-126306LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing modezephyrproject zephyr
CVE-2026-12629PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of servicezephyrproject zephyr
CVE-2026-12522Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fieldszephyrproject zephyr
CVE-2026-12520Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlerszephyrproject zephyr
CVE-2026-12519Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsingzephyrproject zephyr
CVE-2026-12366Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposalzephyrproject zephyr
CVE-2026-12365Use-after-free in Zephyr delayable work-queue cancellation under SMP timing racezephyrproject zephyr
CVE-2026-12364Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and…zephyrproject zephyr
CVE-2026-12363Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0zephyrproject zephyr
CVE-2026-12236Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data lengthzephyrproject zephyr
CVE-2026-12235Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787)zephyrproject zephyr
CVE-2026-12234TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds writezephyrproject zephyr
CVE-2026-12233Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contentionzephyrproject zephyr
CVE-2026-12232Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_propertieszephyrproject zephyr
CVE-2026-12052Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the responsezephyrproject zephyr
CVE-2026-12051NULL pointer dereference in USB DFU device_next download handler (handle_download)zephyrproject zephyr
CVE-2026-11985Cross-thread FPU register leak on ARM when FPU enabled without register sharingzephyrproject zephyr
CVE-2026-11894Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error pathszephyrproject zephyr
CVE-2026-11893Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb)zephyrproject zephyr
CVE-2026-11812UpdateHub: race condition on shared context causes out-of-bounds write and DoSzephyrproject zephyr
CVE-2026-11811Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoSzephyrproject zephyr
CVE-2026-11810NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS)zephyrproject zephyr
CVE-2026-11809UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadatazephyrproject zephyr
CVE-2026-11743Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and writezephyrproject zephyr
CVE-2026-11742Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlockzephyrproject zephyr
CVE-2026-11368Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transferzephyrproject zephyr
CVE-2026-10849Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response bodyzephyrproject zephyr
CVE-2026-10848Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)zephyrproject zephyr
CVE-2026-10774PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoSzephyrproject zephyr
CVE-2026-10773Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)zephyrproject zephyr
CVE-2026-10686Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routerszephyrproject zephyr
CVE-2026-10685Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handlerzephyrproject zephyr
CVE-2026-10684Out-of-bounds read in coredump shell when printing stored-dump target codezephyrproject zephyr
CVE-2026-10683DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)zephyrproject zephyr
CVE-2026-10682Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspacezephyrproject zephyr
CVE-2026-10681SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object…zephyrproject zephyr
CVE-2026-10680Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflowzephyrproject zephyr
CVE-2026-10679Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)zephyrproject zephyr
CVE-2026-10678NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controllerzephyrproject zephyr
CVE-2026-10677Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource poolzephyrproject zephyr
CVE-2026-10675Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)zephyrproject zephyr
CVE-2026-10674DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabledzephyrproject zephyr
CVE-2026-10673Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassemblyzephyrproject zephyr
CVE-2026-10672Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)zephyrproject zephyr
CVE-2026-10671User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)zephyrproject zephyr
CVE-2026-10670User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifierzephyrproject zephyr
CVE-2026-10669Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validationzephyrproject zephyr
CVE-2026-10668Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driverzephyrproject zephyr
CVE-2026-10667SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threadszephyrproject zephyr
CVE-2026-10666Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`zephyrproject zephyr
CVE-2026-10665Heap buffer overflow on WireGuard receive path via unbounded incoming packet lengthzephyrproject zephyr
CVE-2026-10664Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)zephyrproject zephyr
CVE-2026-10663Use-after-free / double-free of the root USB device in the experimental USB host stackzephyrproject zephyr
CVE-2026-10660Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruptionzephyrproject zephyr
CVE-2026-10659NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resumezephyrproject zephyr
CVE-2026-10658Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validationzephyrproject zephyr
CVE-2026-10657Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)zephyrproject zephyr
CVE-2026-10656NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlerszephyrproject zephyr
CVE-2026-10655Use-after-free race in SNTP async client when closing the socket while the socket service is still polling itzephyrproject zephyr
CVE-2026-10654RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classiczephyrproject zephyr
CVE-2026-10653Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unrefzephyrproject zephyr
CVE-2026-10652Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)zephyrproject zephyr
CVE-2026-10651Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)zephyrproject zephyr
CVE-2026-10648NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustionzephyrproject zephyr
CVE-2026-10647Deadlock denial of service in USB CDC-NCM device class on TX enqueue failurezephyrproject zephyr
CVE-2026-10646Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellationzephyrproject zephyr
CVE-2026-10645Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem imagezephyrproject zephyr
CVE-2026-10644Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte bufferzephyrproject zephyr
CVE-2026-10643Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer…zephyrproject zephyr
CVE-2026-10642Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow controlzephyrproject zephyr
CVE-2026-10641Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)zephyrproject zephyr
CVE-2026-10640Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)zephyrproject zephyr
CVE-2026-10639Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`zephyrproject zephyr
CVE-2026-10638Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or errorzephyrproject zephyr
CVE-2026-10637Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Queryzephyrproject zephyr
CVE-2026-10635Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-initzephyrproject zephyr
CVE-2026-10634Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callbackzephyrproject zephyr
CVE-2026-10593Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handlingzephyrproject zephyr
CVE-2026-0849crypto: ATAES132A response length allows stack buffer overflowzephyrproject-rtos Zephyr
CVE-2025-1673Out of bounds read when calling crc16_ansi and strlen in dns_validate_msgzephyrproject-rtos Zephyr
CVE-2025-12890Bluetooth: peripheral: Invalid handling of malformed connection requestzephyrproject-rtos Zephyr
CVE-2025-12035Bluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAPzephyrproject-rtos Zephyr
CVE-2025-10458Bluetooth: le_conn_rsp does not sanitize CID, MTU, MPS valueszephyrproject-rtos Zephyr
CVE-2025-10456Bluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requestszephyrproject-rtos Zephyr
CVE-2024-4785BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zerozephyrproject-rtos Zephyr
CVE-2024-1638Bluetooth characteristic LESC security requirement not enforced without additional flagszephyrproject-rtos Zephyr
CVE-2024-11263arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=yzephyrproject-rtos Zephyr
CVE-2023-5753Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemzephyrproject-rtos Zephyr
CVE-2023-5184Potential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driverzephyrproject-rtos Zephyr
CVE-2023-5139Potential buffer overflow vulnerability in the Zephyr STM32 Crypto driverzephyrproject-rtos Zephyr
CVE-2023-5055L2CAP: Possible Stack based buffer overflow in le_ecred_reconf_req()zephyrproject-rtos Zephyr
CVE-2023-4264Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemzephyrproject-rtos Zephyr
CVE-2023-4263Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driverzephyrproject-rtos Zephyr
CVE-2023-4260Potential off-by-one buffer overflow vulnerability in the Zephyr FS subsystemzephyrproject-rtos Zephyr
CVE-2023-4259Potential buffer overflow vulnerabilities in the Zephyr eS-WiFi driverzephyrproject-rtos Zephyr
CVE-2023-4258bt: mesh: vulnerability in provisioning protocol implementation on provisionee sidezephyrproject-rtos Zephyr
CVE-2023-3725Potential buffer overflow vulnerability in the Zephyr CANbus subsystemzephyrproject-rtos Zephyr
CVE-2022-2741can: denial-of-service can be triggered by a crafted CAN framezephyrproject-rtos zephyr
CVE-2022-1042Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioningzephyrproject-rtos zephyr
CVE-2022-1041Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioningzephyrproject-rtos zephyr
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.