CVE-2026-13479
- EPSS 0.15%
- Veröffentlicht 26.08.2026 14:03:47
- Zuletzt bearbeitet 31.08.2026 23:30:49
The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in bounds; for the CLOCK_SYNC_CMD_A...
CVE-2026-13478
- EPSS 0.11%
- Veröffentlicht 25.08.2026 16:05:39
- Zuletzt bearbeitet 26.08.2026 16:59:23
The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) trea...
CVE-2026-13217
- EPSS 0.51%
- Veröffentlicht 25.08.2026 16:05:38
- Zuletzt bearbeitet 26.08.2026 16:59:23
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without checking the strtok_r return val...
CVE-2026-13216
- EPSS 0.18%
- Veröffentlicht 25.08.2026 16:05:36
- Zuletzt bearbeitet 26.08.2026 16:59:23
The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI config space via pcie_conf_read()) was ...
CVE-2026-13215
- EPSS 0.18%
- Veröffentlicht 25.08.2026 04:37:21
- Zuletzt bearbeitet 28.09.2026 23:10:00
The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic number, revision, inode size and group c...
CVE-2026-13214
- EPSS 0.51%
- Veröffentlicht 25.08.2026 04:37:20
- Zuletzt bearbeitet 28.09.2026 23:10:00
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the cal...
CVE-2026-13213
- EPSS 0.17%
- Veröffentlicht 24.08.2026 17:10:37
- Zuletzt bearbeitet 26.08.2026 16:59:23
The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security even before the applicati...
CVE-2026-13212
- EPSS 0.22%
- Veröffentlicht 24.08.2026 15:43:37
- Zuletzt bearbeitet 26.08.2026 16:59:23
The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used->ring[idx].id is used directly as an index into vq...
CVE-2026-13343
- EPSS 0.23%
- Veröffentlicht 24.08.2026 15:43:36
- Zuletzt bearbeitet 26.08.2026 16:59:23
The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the first two words (res.data[0]...
CVE-2026-9728
- EPSS 0.08%
- Veröffentlicht 24.08.2026 14:28:46
- Zuletzt bearbeitet 26.08.2026 16:59:23
The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct m...