Zephyrproject

Zephyr

270 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 07.08.2026 21:10:23
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued via k_queue_alloc_append/alloc_prepend, the data pointer of an internally allocat...

  • EPSS 0.11%
  • Veröffentlicht 07.08.2026 21:10:23
  • Zuletzt bearbeitet 26.08.2026 16:59:23

The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths with the test (offset + size) > data->size. Because offset is a signed off_t while size is unsigned, a ...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 04.08.2026 14:23:28
  • Zuletzt bearbeitet 01.09.2026 00:16:41

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf des...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 03.08.2026 21:21:32
  • Zuletzt bearbeitet 01.09.2026 00:16:40

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 02.08.2026 16:12:18
  • Zuletzt bearbeitet 01.09.2026 00:16:40

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, toke...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 02.08.2026 14:20:03
  • Zuletzt bearbeitet 01.09.2026 00:16:40

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabl...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 01.08.2026 12:21:17
  • Zuletzt bearbeitet 01.09.2026 00:16:39

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. The guard used msg_type <= sizeof(name) instead of msg_type <= ARRAY_SIZE(name); siz...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 01.08.2026 12:06:41
  • Zuletzt bearbeitet 01.09.2026 00:16:43

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Characteristic Value attribute that carries the application-specified securi...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 31.07.2026 16:16:57
  • Zuletzt bearbeitet 07.08.2026 18:56:38

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-route path (net_route_packet()) and the on-link cross-...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 14:41:47
  • Zuletzt bearbeitet 01.09.2026 00:16:39

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public...