Zephyrproject

Zephyr

270 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.16%
  • Veröffentlicht 16.06.2026 05:19:20
  • Zuletzt bearbeitet 14.07.2026 19:16:46

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded inside the caller-owned struct k_mem_doma...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 15.06.2026 14:16:43
  • Zuletzt bearbeitet 06.08.2026 22:16:42

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 09.06.2026 06:20:23
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf) and the chosen RX pool has a user_data_size small...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 09.06.2026 06:01:02
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy th...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 04.06.2026 20:31:25
  • Zuletzt bearbeitet 22.07.2026 20:10:00

A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c). When the TLS session cache is enabled, tls_session_store() and tls_session_restore() memcpy the caller...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 04.06.2026 19:54:49
  • Zuletzt bearbeitet 22.07.2026 20:10:00

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bounds write. When CONFIG_BT_MESH_OD_PRIV_PROXY_SRV is enabled, the function parses solicitation PDUs fro...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 30.05.2026 07:15:56
  • Zuletzt bearbeitet 22.07.2026 06:10:00

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in socketcan_to_can_frame(). In production builds where ass...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 22.05.2026 07:00:36
  • Zuletzt bearbeitet 23.07.2026 16:10:00

A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potential system crashes. An attacker sends a crafted PTP_MSG_MANAGEMENT message to set an unvalidated negative log_announce_interval val...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 12.05.2026 05:39:02
  • Zuletzt bearbeitet 08.07.2026 13:34:13

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both t...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 11.05.2026 06:16:08
  • Zuletzt bearbeitet 08.07.2026 13:36:24

Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_min_tls_version...