Zephyrproject

Zephyr

270 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 24.06.2026 21:32:05
  • Zuletzt bearbeitet 14.07.2026 19:16:47

The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the interrupt-driven application callback while the TX interrupt mask bit (PL011_IMSC_TXIM) is set, to wor...

  • EPSS 0.17%
  • Veröffentlicht 22.06.2026 23:58:47
  • Zuletzt bearbeitet 14.07.2026 19:16:49

bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the timestamped SDU header (8 bytes) from the inbound HCI ISO Data buffer via net_buf_pull_mem() without first checking buf->len. The...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 22.06.2026 23:54:36
  • Zuletzt bearbeitet 17.07.2026 16:17:12

bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descriptor (type)...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 22.06.2026 23:48:11
  • Zuletzt bearbeitet 14.07.2026 19:16:48

The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len when walking a directory block. ext2_fetch_direntry() guarded only with de_name_len > EXT2_MAX_FILE_NAME, but de_name_len is a ui...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 17.06.2026 13:14:06
  • Zuletzt bearbeitet 14.07.2026 19:16:47

Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in c...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 16.06.2026 13:28:24
  • Zuletzt bearbeitet 14.07.2026 19:16:47

Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-interface ICMP-sent statistics by calling net_pkt_iface(pkt) after net_send_data(pkt) had already returned ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 16.06.2026 13:22:23
  • Zuletzt bearbeitet 06.08.2026 22:16:42

In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_send_data(), and then, on success, calls net_stats_update_icmp_sent(net_pkt_iface(reply)). net_try_send_dat...

  • EPSS 0.35%
  • Veröffentlicht 16.06.2026 13:16:14
  • Zuletzt bearbeitet 17.07.2026 23:16:34

subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_request() and net_icmpv6_send_error(), the post-send statistics update calls net_pkt_iface(reply)/net_pk...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 16.06.2026 13:13:16
  • Zuletzt bearbeitet 14.07.2026 19:16:47

subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network stack's ownership contract (include/zephyr/net/net_core.h, and the explicit warning in subsys/net/ip/...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 16.06.2026 13:12:58
  • Zuletzt bearbeitet 14.07.2026 19:16:47

In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet had been handed to net_send_data(). On the successful-send path the packet's last refe...