Zephyrproject

Zephyr

270 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 26.08.2026 14:03:47
  • Zuletzt bearbeitet 31.08.2026 23:30:49

The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in bounds; for the CLOCK_SYNC_CMD_A...

  • EPSS 0.11%
  • Veröffentlicht 25.08.2026 16:05:39
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) trea...

  • EPSS 0.51%
  • Veröffentlicht 25.08.2026 16:05:38
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without checking the strtok_r return val...

  • EPSS 0.18%
  • Veröffentlicht 25.08.2026 16:05:36
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI config space via pcie_conf_read()) was ...

  • EPSS 0.18%
  • Veröffentlicht 25.08.2026 04:37:21
  • Zuletzt bearbeitet 28.09.2026 23:10:00

The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic number, revision, inode size and group c...

  • EPSS 0.51%
  • Veröffentlicht 25.08.2026 04:37:20
  • Zuletzt bearbeitet 28.09.2026 23:10:00

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the cal...

  • EPSS 0.17%
  • Veröffentlicht 24.08.2026 17:10:37
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security even before the applicati...

  • EPSS 0.22%
  • Veröffentlicht 24.08.2026 15:43:37
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used->ring[idx].id is used directly as an index into vq...

  • EPSS 0.23%
  • Veröffentlicht 24.08.2026 15:43:36
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the first two words (res.data[0]...

  • EPSS 0.08%
  • Veröffentlicht 24.08.2026 14:28:46
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct m...