CVE-2026-10642
- EPSS 0.22%
- Veröffentlicht 24.06.2026 21:32:05
- Zuletzt bearbeitet 14.07.2026 19:16:47
The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the interrupt-driven application callback while the TX interrupt mask bit (PL011_IMSC_TXIM) is set, to wor...
CVE-2026-10658
- EPSS 0.17%
- Veröffentlicht 22.06.2026 23:58:47
- Zuletzt bearbeitet 14.07.2026 19:16:49
bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the timestamped SDU header (8 bytes) from the inbound HCI ISO Data buffer via net_buf_pull_mem() without first checking buf->len. The...
CVE-2026-10651
- EPSS 0.28%
- Veröffentlicht 22.06.2026 23:54:36
- Zuletzt bearbeitet 17.07.2026 16:17:12
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descriptor (type)...
CVE-2026-10645
- EPSS 0.15%
- Veröffentlicht 22.06.2026 23:48:11
- Zuletzt bearbeitet 14.07.2026 19:16:48
The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len when walking a directory block. ext2_fetch_direntry() guarded only with de_name_len > EXT2_MAX_FILE_NAME, but de_name_len is a ui...
CVE-2026-10641
- EPSS 0.28%
- Veröffentlicht 17.06.2026 13:14:06
- Zuletzt bearbeitet 14.07.2026 19:16:47
Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in c...
CVE-2026-10640
- EPSS 0.37%
- Veröffentlicht 16.06.2026 13:28:24
- Zuletzt bearbeitet 14.07.2026 19:16:47
Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-interface ICMP-sent statistics by calling net_pkt_iface(pkt) after net_send_data(pkt) had already returned ...
CVE-2026-10639
- EPSS 0.23%
- Veröffentlicht 16.06.2026 13:22:23
- Zuletzt bearbeitet 06.08.2026 22:16:42
In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_send_data(), and then, on success, calls net_stats_update_icmp_sent(net_pkt_iface(reply)). net_try_send_dat...
CVE-2026-10638
- EPSS 0.35%
- Veröffentlicht 16.06.2026 13:16:14
- Zuletzt bearbeitet 17.07.2026 23:16:34
subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_request() and net_icmpv6_send_error(), the post-send statistics update calls net_pkt_iface(reply)/net_pk...
CVE-2026-10637
- EPSS 0.3%
- Veröffentlicht 16.06.2026 13:13:16
- Zuletzt bearbeitet 14.07.2026 19:16:47
subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network stack's ownership contract (include/zephyr/net/net_core.h, and the explicit warning in subsys/net/ip/...
CVE-2026-10636
- EPSS 0.31%
- Veröffentlicht 16.06.2026 13:12:58
- Zuletzt bearbeitet 14.07.2026 19:16:47
In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet had been handed to net_send_data(). On the successful-send path the packet's last refe...