zephyrproject zephyr
39 known vulnerabilities in zephyrproject zephyr, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-19185 CVSS 7.8 high The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data…
- CVE-2026-19184 CVSS 8.4 high The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes…
- CVE-2026-17053 CVSS 4.4 medium The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in…
- CVE-2026-18747 CVSS 6.8 medium The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then…
- CVE-2026-18746 CVSS 5.9 medium parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option…
- CVE-2026-18417 CVSS 6.5 medium The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field…
- CVE-2026-18416 CVSS 3.7 low The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource path against the URI…
- CVE-2026-18415 CVSS 6.3 medium ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer…
- CVE-2026-18414 CVSS 7.8 high The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct…
- CVE-2026-18413 CVSS 7.8 high The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct…
- CVE-2026-16513 CVSS 7.8 high The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0)…
- CVE-2026-17054 CVSS 5.3 medium The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in…
- CVE-2026-15890 CVSS 5.3 medium The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in…
- CVE-2026-17052 CVSS 7.8 high The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c…
- CVE-2026-17051 CVSS 6.0 medium The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose()…
- CVE-2026-17050 CVSS 5.7 medium The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap…
- CVE-2026-16515 CVSS 4.7 medium net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer…
- CVE-2026-16514 CVSS 4.3 medium gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message…
- CVE-2026-16512 CVSS 3.1 low gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on…
- CVE-2026-14986 CVSS 6.8 medium The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE)…
- CVE-2026-16148 CVSS 4.6 medium The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work…
- CVE-2026-16147 CVSS 6.8 medium The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control…
- CVE-2026-15924 CVSS 5.9 medium Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client…
- CVE-2026-15893 CVSS 6.5 medium net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as…
- CVE-2026-15923 CVSS 4.6 medium The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size…
- CVE-2026-15892 CVSS 5.3 medium The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in…
- CVE-2026-15891 CVSS 7.5 high The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries…
- CVE-2026-15461 CVSS 5.3 medium The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic…
- CVE-2026-15460 CVSS 5.4 medium The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound…
- CVE-2026-14697 CVSS 6.5 medium net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data…