CVE-2026-15894
- EPSS 0.31%
- Veröffentlicht 07.10.2026 08:55:25
- Zuletzt bearbeitet 07.10.2026 18:17:19
The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as...
CVE-2026-19186
- EPSS 0.21%
- Veröffentlicht 07.10.2026 08:55:22
- Zuletzt bearbeitet 07.10.2026 19:17:36
ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All...
CVE-2026-19185
- EPSS 0.11%
- Veröffentlicht 05.10.2026 08:06:29
- Zuletzt bearbeitet 06.10.2026 15:27:05
The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements ...
CVE-2026-19184
- EPSS 0.1%
- Veröffentlicht 05.10.2026 08:06:22
- Zuletzt bearbeitet 06.10.2026 15:27:05
The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data-...
CVE-2026-17053
- EPSS 0.09%
- Veröffentlicht 01.10.2026 15:08:52
- Zuletzt bearbeitet 02.10.2026 18:44:11
The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded ...
CVE-2026-18417
- EPSS 0.18%
- Veröffentlicht 29.09.2026 00:17:04
- Zuletzt bearbeitet 30.09.2026 14:17:27
The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and...
CVE-2026-18746
- EPSS 0.25%
- Veröffentlicht 29.09.2026 00:17:04
- Zuletzt bearbeitet 30.09.2026 14:17:27
parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block ...
CVE-2026-18747
- EPSS 0.12%
- Veröffentlicht 29.09.2026 00:17:04
- Zuletzt bearbeitet 30.09.2026 14:17:27
The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/trans...
CVE-2026-18413
- EPSS 0.12%
- Veröffentlicht 28.09.2026 21:17:17
- Zuletzt bearbeitet 30.09.2026 21:17:09
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written bey...
CVE-2026-18414
- EPSS 0.12%
- Veröffentlicht 28.09.2026 21:17:17
- Zuletzt bearbeitet 30.09.2026 16:17:11
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written bey...