Zephyrproject

Zephyr

270 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 07.10.2026 08:55:25
  • Zuletzt bearbeitet 07.10.2026 18:17:19

The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as...

  • EPSS 0.21%
  • Veröffentlicht 07.10.2026 08:55:22
  • Zuletzt bearbeitet 07.10.2026 19:17:36

ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All...

  • EPSS 0.11%
  • Veröffentlicht 05.10.2026 08:06:29
  • Zuletzt bearbeitet 06.10.2026 15:27:05

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements ...

  • EPSS 0.1%
  • Veröffentlicht 05.10.2026 08:06:22
  • Zuletzt bearbeitet 06.10.2026 15:27:05

The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data-...

  • EPSS 0.09%
  • Veröffentlicht 01.10.2026 15:08:52
  • Zuletzt bearbeitet 02.10.2026 18:44:11

The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded ...

  • EPSS 0.18%
  • Veröffentlicht 29.09.2026 00:17:04
  • Zuletzt bearbeitet 30.09.2026 14:17:27

The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and...

  • EPSS 0.25%
  • Veröffentlicht 29.09.2026 00:17:04
  • Zuletzt bearbeitet 30.09.2026 14:17:27

parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block ...

  • EPSS 0.12%
  • Veröffentlicht 29.09.2026 00:17:04
  • Zuletzt bearbeitet 30.09.2026 14:17:27

The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/trans...

  • EPSS 0.12%
  • Veröffentlicht 28.09.2026 21:17:17
  • Zuletzt bearbeitet 30.09.2026 21:17:09

The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written bey...

  • EPSS 0.12%
  • Veröffentlicht 28.09.2026 21:17:17
  • Zuletzt bearbeitet 30.09.2026 16:17:11

The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written bey...