CVE-2026-10635
- EPSS 0.16%
- Veröffentlicht 16.06.2026 05:19:20
- Zuletzt bearbeitet 14.07.2026 19:16:46
On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded inside the caller-owned struct k_mem_doma...
CVE-2026-10634
- EPSS 0.27%
- Veröffentlicht 15.06.2026 14:16:43
- Zuletzt bearbeitet 06.08.2026 22:16:42
Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock...
CVE-2026-5068
- EPSS 0.45%
- Veröffentlicht 09.06.2026 06:20:23
- Zuletzt bearbeitet 23.07.2026 08:10:00
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf) and the chosen RX pool has a user_data_size small...
CVE-2026-5067
- EPSS 0.64%
- Veröffentlicht 09.06.2026 06:01:02
- Zuletzt bearbeitet 23.07.2026 08:10:00
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy th...
CVE-2026-5066
- EPSS 0.32%
- Veröffentlicht 04.06.2026 20:31:25
- Zuletzt bearbeitet 22.07.2026 20:10:00
A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c). When the TLS session cache is enabled, tls_session_store() and tls_session_restore() memcpy the caller...
CVE-2026-5589
- EPSS 0.26%
- Veröffentlicht 04.06.2026 19:54:49
- Zuletzt bearbeitet 22.07.2026 20:10:00
An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bounds write. When CONFIG_BT_MESH_OD_PRIV_PROXY_SRV is enabled, the function parses solicitation PDUs fro...
CVE-2026-5071
- EPSS 0.17%
- Veröffentlicht 30.05.2026 07:15:56
- Zuletzt bearbeitet 22.07.2026 06:10:00
The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in socketcan_to_can_frame(). In production builds where ass...
CVE-2026-5072
- EPSS 0.3%
- Veröffentlicht 22.05.2026 07:00:36
- Zuletzt bearbeitet 23.07.2026 16:10:00
A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potential system crashes. An attacker sends a crafted PTP_MSG_MANAGEMENT message to set an unvalidated negative log_announce_interval val...
CVE-2026-1681
- EPSS 0.14%
- Veröffentlicht 12.05.2026 05:39:02
- Zuletzt bearbeitet 08.07.2026 13:34:13
Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both t...
CVE-2026-1677
- EPSS 0.24%
- Veröffentlicht 11.05.2026 06:16:08
- Zuletzt bearbeitet 08.07.2026 13:36:24
Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_min_tls_version...