Zephyrproject

Zephyr

270 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 30.06.2026 15:50:46
  • Zuletzt bearbeitet 06.08.2026 22:16:43

Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which validated only the fixed RR header (type, class, TTL, rdlength) and accepted any attacker-declared rdlength, including one extending p...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 29.06.2026 22:51:27
  • Zuletzt bearbeitet 14.07.2026 19:16:48

mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of smp_packet_alloc() before checking it for NULL. smp_packet_alloc() uses net_buf_alloc(K_NO_WAIT) against the shared MCUmgr packet po...

Exploit
  • EPSS 0.91%
  • Veröffentlicht 29.06.2026 22:15:22
  • Zuletzt bearbeitet 17.07.2026 16:17:19

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both the HTTP/1 an...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 29.06.2026 22:09:10
  • Zuletzt bearbeitet 06.08.2026 22:18:32

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wrong operator p...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 29.06.2026 21:39:08
  • Zuletzt bearbeitet 06.08.2026 22:16:43

The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit callback cdc_ncm_send(). When the enqueue fails, the function still calls k_sem_take(&data->sync_sem, K_...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 28.06.2026 04:28:22
  • Zuletzt bearbeitet 14.07.2026 19:16:46

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c), the handler writes attacker-controlled QoS fields...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 28.06.2026 04:04:11
  • Zuletzt bearbeitet 06.08.2026 22:16:43

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS resolver query. The socket layer w...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 28.06.2026 04:02:47
  • Zuletzt bearbeitet 14.07.2026 19:16:47

The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains an out-of-bounds write in its asynchronous (DMA) receive path. When uart_rx_enable() is invoked with a one-byte receive buffer (le...

  • EPSS 0.13%
  • Veröffentlicht 27.06.2026 22:59:22
  • Zuletzt bearbeitet 06.08.2026 22:16:43

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg->msg_controllen < pktinfo_len) before writing a full c...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 25.06.2026 16:27:17
  • Zuletzt bearbeitet 06.07.2026 19:54:08

Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number of maliciously fragmented IPv6 packets. When such a packet is handled by the fragment-header processing path, the associated R...