CVE-2026-10652
- EPSS 0.31%
- Veröffentlicht 30.06.2026 15:50:46
- Zuletzt bearbeitet 06.08.2026 22:16:43
Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which validated only the fixed RR header (type, class, TTL, rdlength) and accepted any attacker-declared rdlength, including one extending p...
CVE-2026-10648
- EPSS 0.15%
- Veröffentlicht 29.06.2026 22:51:27
- Zuletzt bearbeitet 14.07.2026 19:16:48
mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of smp_packet_alloc() before checking it for NULL. smp_packet_alloc() uses net_buf_alloc(K_NO_WAIT) against the shared MCUmgr packet po...
CVE-2026-8023
- EPSS 0.91%
- Veröffentlicht 29.06.2026 22:15:22
- Zuletzt bearbeitet 17.07.2026 16:17:19
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both the HTTP/1 an...
CVE-2026-7656
- EPSS 0.31%
- Veröffentlicht 29.06.2026 22:09:10
- Zuletzt bearbeitet 06.08.2026 22:18:32
The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wrong operator p...
CVE-2026-10647
- EPSS 0.21%
- Veröffentlicht 29.06.2026 21:39:08
- Zuletzt bearbeitet 06.08.2026 22:16:43
The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit callback cdc_ncm_send(). When the enqueue fails, the function still calls k_sem_take(&data->sync_sem, K_...
CVE-2026-10593
- EPSS 0.28%
- Veröffentlicht 28.06.2026 04:28:22
- Zuletzt bearbeitet 14.07.2026 19:16:46
The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c), the handler writes attacker-controlled QoS fields...
CVE-2026-10646
- EPSS 0.32%
- Veröffentlicht 28.06.2026 04:04:11
- Zuletzt bearbeitet 06.08.2026 22:16:43
Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS resolver query. The socket layer w...
CVE-2026-10644
- EPSS 0.23%
- Veröffentlicht 28.06.2026 04:02:47
- Zuletzt bearbeitet 14.07.2026 19:16:47
The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains an out-of-bounds write in its asynchronous (DMA) receive path. When uart_rx_enable() is invoked with a one-byte receive buffer (le...
CVE-2026-10643
- EPSS 0.13%
- Veröffentlicht 27.06.2026 22:59:22
- Zuletzt bearbeitet 06.08.2026 22:16:43
Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg->msg_controllen < pktinfo_len) before writing a full c...
CVE-2026-13351
- EPSS 0.32%
- Veröffentlicht 25.06.2026 16:27:17
- Zuletzt bearbeitet 06.07.2026 19:54:08
Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number of maliciously fragmented IPv6 packets. When such a packet is handled by the fragment-header processing path, the associated R...