vciy

CVEs we hold for Zephyrproject-rtos

Records whose assigning authority named Zephyrproject-rtos as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-5590net: ip/tcp: Null pointer dereference can be triggered by a race conditionzephyrproject-rtos Zephyr
CVE-2026-5589Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.zephyrproject-rtos Zephyr
CVE-2026-5072ptp: Potential Denial of Service via PTP Interval Shiftzephyrproject-rtos Zephyr
CVE-2026-5071can: Local Denial of Service via SocketCAN Sendzephyrproject-rtos Zephyr
CVE-2026-5068bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_datazephyrproject-rtos Zephyr
CVE-2026-5067Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Keyzephyrproject-rtos Zephyr
CVE-2026-5066net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect functionzephyrproject-rtos Zephyr
CVE-2026-4179stm32: usb: Infinite while loop in Interrupt Handlerzephyrproject-rtos Zephyr
CVE-2026-1681net: Stack Overflow with Ping (to own IP Address) via Shellzephyrproject-rtos Zephyr
CVE-2026-1679net: eswifi socket send payload length not boundedzephyrproject-rtos Zephyr
CVE-2026-1678dns: memory‑safety issue in the DNS name parserzephyrproject-rtos Zephyr
CVE-2026-1677net: TLS 1.2 connections allowed on TLS 1.3 socketszephyrproject-rtos Zephyr
CVE-2026-13351net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packetszephyrproject-rtos Zephyr
CVE-2026-0849crypto: ATAES132A response length allows stack buffer overflowzephyrproject-rtos Zephyr
CVE-2025-9558Bluetooth: Mesh: Out-of-Bound Write in gen_prov_startzephyrproject-rtos Zephyr
CVE-2025-9557Bluetooth: Mesh: Out-of-Bound Write in gen_prov_contzephyrproject-rtos Zephyr
CVE-2025-9408Userspace privilege escalation vulnerability on Cortex Mzephyrproject-rtos Zephyr
CVE-2025-7403Bluetooth: bt_conn_tx_processor unsafe handlingzephyrproject-rtos Zephyr
CVE-2025-2962Infinite loop in dns_copy_qnamezephyrproject-rtos Zephyr
CVE-2025-1675Out of bounds read in dns_copy_qnamezephyrproject-rtos Zephyr
CVE-2025-1674Out of bounds read when unpacking DNS answerszephyrproject-rtos Zephyr
CVE-2025-1673Out of bounds read when calling crc16_ansi and strlen in dns_validate_msgzephyrproject-rtos Zephyr
CVE-2025-12899net: icmp: Out of bound memory readzephyrproject-rtos Zephyr
CVE-2025-12890Bluetooth: peripheral: Invalid handling of malformed connection requestzephyrproject-rtos Zephyr
CVE-2025-12035Bluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAPzephyrproject-rtos Zephyr
CVE-2025-10458Bluetooth: le_conn_rsp does not sanitize CID, MTU, MPS valueszephyrproject-rtos Zephyr
CVE-2025-10457Bluetooth: Out-Of-Context le_conn_rsp Handlingzephyrproject-rtos Zephyr
CVE-2025-10456Bluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requestszephyrproject-rtos Zephyr
CVE-2024-8798Bluetooth: classic: avdtp: missing buffer length checkzephyrproject-rtos Zephyr
CVE-2024-6444Bluetooth: ots: missing buffer length checkzephyrproject-rtos Zephyr
CVE-2024-6443zephyr: out-of-bound read in utf8_trunczephyrproject-rtos Zephyr
CVE-2024-6442Bluetooth: ASCS Unchecked tailroom of the response bufferzephyrproject-rtos Zephyr
CVE-2024-6259BT: HCI: adv_ext_report Improper discarding in adv_ext_reportzephyrproject-rtos Zephyr
CVE-2024-6258BT: Missing length checks of net_buf in rfcomm_handle_datazephyrproject-rtos Zephyr
CVE-2024-6137BT: Classic: SDP OOB access in get_att_search_listzephyrproject-rtos Zephyr
CVE-2024-6135BT:Classic: Multiple missing buf length checkszephyrproject-rtos Zephyr
CVE-2024-5931BT: Unchecked user input in bap_broadcast_assistantzephyrproject-rtos Zephyr
CVE-2024-5754BT: Encryption procedure host vulnerabilityzephyrproject-rtos Zephyr
CVE-2024-4785BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zerozephyrproject-rtos Zephyr
CVE-2024-3332bt: host/smp: DoS caused by null pointer dereferencezephyrproject-rtos Zephyr
CVE-2024-3077Bluetooth: integer underflow in gatt_find_info_rspzephyrproject-rtos Zephyr
CVE-2024-1638Bluetooth characteristic LESC security requirement not enforced without additional flagszephyrproject-rtos Zephyr
CVE-2024-11263arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=yzephyrproject-rtos Zephyr
CVE-2024-10395net: lib: http_server: Buffer Under-readzephyrproject-rtos Zephyr
CVE-2023-7060Missing Security Control in Zephyr OS IP Packet Handlingzephyrproject-rtos Zephyr
CVE-2023-6881fs: fuse: buffer overflow vulnerability in the Zephyr FSzephyrproject-rtos Zephyr
CVE-2023-6749Unchecked user input length in the Zephyr Settings Shellzephyrproject-rtos Zephyr
CVE-2023-6249ipm: signed to unsigned conversion problem in esp32_ipm_sendzephyrproject-rtos Zephyr
CVE-2023-5779can: out of bounds in remove_rx_filter functionzephyrproject-rtos Zephyr
CVE-2023-5753Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemzephyrproject-rtos Zephyr
CVE-2023-5563no title heldzephyrproject-rtos Zephyr
CVE-2023-5184Potential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driverzephyrproject-rtos Zephyr
CVE-2023-5139Potential buffer overflow vulnerability in the Zephyr STM32 Crypto driverzephyrproject-rtos Zephyr
CVE-2023-5055L2CAP: Possible Stack based buffer overflow in le_ecred_reconf_req()zephyrproject-rtos Zephyr
CVE-2023-4424bt: hci: DoS and possible RCEzephyrproject-rtos Zephyr
CVE-2023-4265Buffer overflow in Zephyr USBzephyrproject-rtos Zephyr
CVE-2023-4264Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemzephyrproject-rtos Zephyr
CVE-2023-4263Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driverzephyrproject-rtos Zephyr
CVE-2023-4260Potential off-by-one buffer overflow vulnerability in the Zephyr FS subsystemzephyrproject-rtos Zephyr
CVE-2023-4259Potential buffer overflow vulnerabilities in the Zephyr eS-WiFi driverzephyrproject-rtos Zephyr
CVE-2023-4258bt: mesh: vulnerability in provisioning protocol implementation on provisionee sidezephyrproject-rtos Zephyr
CVE-2023-4257Unchecked user input length in the Zephyr WiFi shell modulezephyrproject-rtos Zephyr
CVE-2023-3725Potential buffer overflow vulnerability in the Zephyr CANbus subsystemzephyrproject-rtos Zephyr
CVE-2023-2234BT HCI host union variant confusionzephyrproject-rtos Zephyr
CVE-2023-1902HCI Connection Creation Dangling State Reference Re-usezephyrproject-rtos Zephyr
CVE-2023-1901HCI send_sync Dangling Semaphore Reference Re-usezephyrproject-rtos Zephyr
CVE-2023-0779net: shell: Improper input validationzephyrproject-rtos zephyr
CVE-2023-0397DoS: Invalid Initialization in le_read_buffer_size_completezephyrproject-rtos zephyr
CVE-2023-0396Buffer Overreads in Bluetooth HCIzephyrproject-rtos zephyr
CVE-2023-0359ipv6: Missing ipv6 nullptr-check in handle_ra_inputzephyrproject-rtos Zephyr
CVE-2022-3806Bluetooth HCI Error Handling Double Freezephyrproject-rtos zephyr
CVE-2022-2993bt: host: Wrong key validation checkzephyrproject-rtos zephyr
CVE-2022-2741can: denial-of-service can be triggered by a crafted CAN framezephyrproject-rtos zephyr
CVE-2022-1841Out-of-bound write in tcp_flagszephyrproject-rtos zephyr
CVE-2022-1042Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioningzephyrproject-rtos zephyr
CVE-2022-1041Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioningzephyrproject-rtos zephyr
CVE-2022-0553Possible to retrieve uncrypted firmware imagezephyrproject-rtos zephyr
CVE-2021-3966Usb bluetooth device ACL read cb buffer overflowzephyrproject-rtos zephyr
CVE-2021-3861The RNDIS USB device class includes a buffer overflow vulnerabilityzephyrproject-rtos zephyr
CVE-2021-3835Buffer overflow in usb device classzephyrproject-rtos zephyr
CVE-2021-3625Buffer overflow in Zephyr USB DFU DNLOADzephyrproject-rtos zephyr
CVE-2021-3581Buffer Access with Incorrect Length Value in zephyrzephyrproject-rtos zephyr
CVE-2021-3510Zephyr JSON decoder incorrectly decodes array of arrayzephyrproject-rtos zephyr
CVE-2021-3455Disconnecting L2CAP channel right after invalid ATT request leads freezezephyrproject-rtos zephyr
CVE-2021-3454Truncated L2CAP K-frame causes assertion failurezephyrproject-rtos zephyr
CVE-2021-3436BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is knownzephyrproject-rtos zephyr
CVE-2021-3435L2CAP: Information leakage in le_ecred_conn_req()zephyrproject-rtos zephyr
CVE-2021-3434L2CAP: Stack based buffer overflow in le_ecred_conn_req()zephyrproject-rtos zephyr
CVE-2021-3433BT: Invalid channel map in CONNECT_IND results to Deadlockzephyrproject-rtos zephyr
CVE-2021-3432BT: Invalid interval in CONNECT_IND leads to Division by Zerozephyrproject-rtos zephyr
CVE-2021-3431BT: Assertion failure on repeated LL_FEATURE_REQzephyrproject-rtos zephyr
CVE-2021-3430BT: Assertion failure on repeated LL_CONNECTION_PARAM_REQzephyrproject-rtos zephyr
CVE-2021-3330RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyrzephyrproject-rtos zephyr
CVE-2021-3329DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layerzephyrproject-rtos zephyr
CVE-2021-3323Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyrzephyrproject-rtos zephyr
CVE-2021-3322Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyrzephyrproject-rtos zephyr
CVE-2021-3321Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removalzephyrproject-rtos zephyr
CVE-2021-3320Type Confusion in 802154 ACK Frames Handlingzephyrproject-rtos zephyr
CVE-2021-3319DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresseszephyrproject-rtos zephyr
CVE-2020-13603Integer Overflow in memory allocating functionszephyrproject-rtos zephyr
CVE-2020-13602Remote Denial of Service in LwM2M do_write_op_tlvzephyrproject-rtos zephyr
CVE-2020-13601Possible read out of bounds in dns readzephyrproject-rtos zephyr
CVE-2020-13600Malformed SPI in response for eswifi can corrupt kernel memoryzephyrproject-rtos zephyr
CVE-2020-13599Security problem with settings and littlefszephyrproject-rtos zephyr
CVE-2020-13598FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_statzephyrproject-rtos zephyr
CVE-2020-10072Improper Handling of Insufficient Permissions or Privileges in zephyrzephyrproject-rtos zephyr
CVE-2020-10071Insufficient publish message length validation in MQTTzephyrproject-rtos zephyr
CVE-2020-10070MQTT buffer overflow on receive bufferzephyrproject-rtos zephyr
CVE-2020-10069Zephyr Bluetooth unchecked packet data results in denial of servicezephyrproject-rtos zephyr
CVE-2020-10068Zephyr Bluetooth DLE duplicate requests vulnerabilityzephyrproject-rtos zephyr
CVE-2020-10067Integer Overflow In is_in_region Allows User Thread To Access Kernel Memoryzephyrproject-rtos zephyr
CVE-2020-10066Incorrect Error Handling in Bluetooth HCI corezephyrproject-rtos zephyr
CVE-2020-10065Missing Size Checks in Bluetooth HCI over SPIzephyrproject-rtos zephyr
CVE-2020-10064Improper Input Frame Validation in ieee802154 Processingzephyrproject-rtos zephyr
CVE-2020-10063Remote Denial of Service in CoAP Option Parsing Due To Integer Overflowzephyrproject-rtos zephyr
CVE-2020-10062Packet length decoding error in MQTTzephyrproject-rtos zephyr
CVE-2020-10061Error handling invalid packet sequencezephyrproject-rtos zephyr
CVE-2020-10060UpdateHub Might Dereference An Uninitialized Pointerzephyrproject-rtos zephyr
CVE-2020-10059UpdateHub Module Explicitly Disables TLS Verificationzephyrproject-rtos zephyr
CVE-2020-10058Multiple Syscalls In kscan Subsystem Performs No Argument Validationzephyrproject-rtos zephyr
CVE-2020-10028Multiple Syscalls In GPIO Subsystem Performs No Argument Validationzephyrproject-rtos zephyr
CVE-2020-10027ARC Platform Uses Signed Integer Comparison When Validating Syscall Numberszephyrproject-rtos zephyr
CVE-2020-10024ARM Platform Uses Signed Integer Comparison When Validating Syscall Numberszephyrproject-rtos zephyr
CVE-2020-10023Shell Subsystem Contains a Buffer Overflow Vulnerability In shell_spaces_trimzephyrproject-rtos zephyr
CVE-2020-10022UpdateHub Module Copies a Variable-Size Hash String Into a Fixed-Size Arrayzephyrproject-rtos zephyr
CVE-2020-10021Out-of-bounds write in USB Mass Storage with unaligned sizeszephyrproject-rtos zephyr
CVE-2020-10019Buffer Overflow in USB DFU requested lengthzephyrproject-rtos zephyr

127 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.