Zephyrproject

Zephyr

270 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 11.08.2026 05:51:40
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_parameters) and GET_NTB_INPUT_SIZE (8-byte struct nt...

  • EPSS 0.17%
  • Veröffentlicht 11.08.2026 05:31:19
  • Zuletzt bearbeitet 01.09.2026 00:16:42

The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, buf->len) and pa...

  • EPSS 0.16%
  • Veröffentlicht 11.08.2026 05:17:11
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates the bt_hci_driver_api.send() buffer-ownership contract. That contract (documented at include/zephyr/dr...

  • EPSS 0.09%
  • Veröffentlicht 11.08.2026 05:17:11
  • Zuletzt bearbeitet 01.09.2026 00:16:42

On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI permit the compiler to emit hardware FP instructions in any function, even code...

  • EPSS 0.17%
  • Veröffentlicht 11.08.2026 05:08:51
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on su...

  • EPSS 0.08%
  • Veröffentlicht 10.08.2026 23:09:17
  • Zuletzt bearbeitet 01.09.2026 00:16:41

The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds...

  • EPSS 0.25%
  • Veröffentlicht 10.08.2026 22:55:17
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret...

  • EPSS 0.12%
  • Veröffentlicht 10.08.2026 22:40:26
  • Zuletzt bearbeitet 26.08.2026 16:59:23

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was...

  • EPSS 0.27%
  • Veröffentlicht 10.08.2026 20:36:33
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a heap buffer (metadata) that is correctly NU...

  • EPSS 0.33%
  • Veröffentlicht 10.08.2026 20:23:23
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the...