CVE-2026-18415
- EPSS 0.1%
- Veröffentlicht 28.09.2026 21:17:17
- Zuletzt bearbeitet 30.09.2026 16:17:12
ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenev...
CVE-2026-18416
- EPSS 0.22%
- Veröffentlicht 28.09.2026 21:17:17
- Zuletzt bearbeitet 30.09.2026 16:17:12
The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource path against the URI carried in a Uri-Query href= option. That URI is not NUL terminated, but the inner character loop advanced its ...
CVE-2026-16513
- EPSS 0.11%
- Veröffentlicht 28.09.2026 21:17:16
- Zuletzt bearbeitet 30.09.2026 21:17:09
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop ite...
CVE-2026-17054
- EPSS 0.17%
- Veröffentlicht 21.09.2026 21:16:05
- Zuletzt bearbeitet 22.09.2026 19:41:24
The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and passed it to ...
CVE-2026-15890
- EPSS 0.06%
- Veröffentlicht 21.09.2026 21:16:04
- Zuletzt bearbeitet 22.09.2026 19:41:24
The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized function-local stat...
CVE-2026-17052
- EPSS 0.12%
- Veröffentlicht 21.09.2026 18:35:30
- Zuletzt bearbeitet 22.09.2026 19:41:24
The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and event_count output pointers to the d...
- EPSS 0.11%
- Veröffentlicht 21.09.2026 16:41:24
- Zuletzt bearbeitet 22.09.2026 19:41:24
The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose(). It read the peer-written doorbell register, extracted the payload length with IPC_HEADER_GET_LENGTH(), and pass...
CVE-2026-17050
- EPSS 0.16%
- Veröffentlicht 21.09.2026 16:41:23
- Zuletzt bearbeitet 22.09.2026 19:41:24
The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a failed full-leng...
CVE-2026-16515
- EPSS 0.2%
- Veröffentlicht 18.09.2026 14:30:13
- Zuletzt bearbeitet 18.09.2026 19:11:57
net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). It did not check whether the triggering packet's source address identifie...
CVE-2026-16514
- EPSS 0.24%
- Veröffentlicht 18.09.2026 14:30:11
- Zuletzt bearbeitet 18.09.2026 19:11:57
gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attacker-controlle...