CVE-2026-16512
- EPSS 0.17%
- Veröffentlicht 18.09.2026 14:30:10
- Zuletzt bearbeitet 18.09.2026 19:11:57
gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) bytes of payloa...
CVE-2026-14986
- EPSS 0.18%
- Veröffentlicht 14.09.2026 22:07:46
- Zuletzt bearbeitet 18.09.2026 19:11:57
The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO interrupt handle...
CVE-2026-16148
- EPSS 0.17%
- Veröffentlicht 14.09.2026 19:33:47
- Zuletzt bearbeitet 14.09.2026 21:10:41
The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2.c. This work...
CVE-2026-16147
- EPSS 0.18%
- Veröffentlicht 14.09.2026 19:33:46
- Zuletzt bearbeitet 14.09.2026 21:10:41
The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transfer buffer is obtained with udc_buf_peek() (which does not dequeue it);...
CVE-2026-15924
- EPSS 0.31%
- Veröffentlicht 14.09.2026 19:33:45
- Zuletzt bearbeitet 14.09.2026 21:10:41
Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and read it — tls_session_save(), tls...
CVE-2026-15893
- EPSS 0.2%
- Veröffentlicht 14.09.2026 18:49:55
- Zuletzt bearbeitet 14.09.2026 21:10:41
net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable = ...
CVE-2026-15923
- EPSS 0.17%
- Veröffentlicht 14.09.2026 16:12:52
- Zuletzt bearbeitet 14.09.2026 21:10:41
The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value func->cis.max_blk_size is decoded...
CVE-2026-15892
- EPSS 0.28%
- Veröffentlicht 13.09.2026 22:46:16
- Zuletzt bearbeitet 14.09.2026 21:10:41
The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_mall...
CVE-2026-15891
- EPSS 0.34%
- Veröffentlicht 13.09.2026 22:46:15
- Zuletzt bearbeitet 14.09.2026 21:10:41
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. Th...
CVE-2026-15461
- EPSS 0.16%
- Veröffentlicht 10.09.2026 14:34:21
- Zuletzt bearbeitet 10.09.2026 17:17:01
The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers...