Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.18% | — | Zephyr RtosAI | 31/8/2026 | 1/9/2026 | net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pending_queue is already non-empty (an NS is already outstanding), the function appends the data packet and returns early… | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | Zephyr RtosAI | 31/8/2026 | 1/9/2026 | When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface is handled. For frames that must also be delivered to the local stack, the code called eth_bridge_handle_locally() and… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Zephyrproject ZephyrAI | 31/8/2026 | 1/9/2026 | The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (string_length > buflen), which accepts a string whose length is exactly buflen. After memcpy() fills the whole buffer,… | |
| Pendiente de análisis | Baja (3.1) | 0.10% | — | Zephyr RtosAI | 31/8/2026 | 1/9/2026 | The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchronization. The allocation helpers (i3c_ibi_work_enqueue, i3c_ibi_work_enqueue_target_irq, i3c_ibi_work_enqueue_hotjoin,… | |
| Pendiente de análisis | Media (6.4) | 0.16% | — | Silabs Siwx917AIZephyrproject ZephyrAI | 31/8/2026 | 1/9/2026 | The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the net_pkt is owned by the L2/networking stack; the driver only borrows it to copy the frame bytes into a local net_buf. Before the fix, after… | |
| Analizada | Media (5.4) | 0.26% | — | Zephyrproject Zephyr | 26/8/2026 | 31/8/2026 | The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In tlv_mgmt_post_recv(), the PTP_MGMT_TIME case casts mgmt_tlv->data to a 10-byte struct ptp_timestamp and reads it (then byte-swaps and writes it back) without first checking that the TLV data field is… | |
| Analizada | Baja (3.1) | 0.26% | — | Zephyrproject Zephyr | 26/8/2026 | 31/8/2026 | The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain before each access. The loop's only bound is rx_pos < len; after consuming the one-byte command id… | |
| Analizada | Media (4.3) | 0.24% | — | Zephyrproject Zephyr | 26/8/2026 | 31/8/2026 | The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in bounds; for the CLOCK_SYNC_CMD_APP_TIME (AppTimeAns) command the handler then reads a 4-byte time… | |
| Pendiente de análisis | Media (5.5) | 0.11% | — | Zephyr Ext2 Filesystem DriverAI | 25/8/2026 | 26/8/2026 | The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) treats its argument as a number of bits and reads one bitmap byte per… | |
| Pendiente de análisis | Media (5.9) | 0.51% | — | Zephyrproject ZephyrAI | 25/8/2026 | 26/8/2026 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without checking the strtok_r return value. When the server-supplied uid is empty or contains no - delimiter,… | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | Zephyr RtosAIVirtio PCIAI | 25/8/2026 | 26/8/2026 | The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI config space via pcie_conf_read()) was only checked with assert(tmp.cap_len == cap_struct_size). That assert… | |
| Pendiente de análisis | Media (6.8) | 0.18% | — | Zephyr Ext2 Filesystem DriverAI | 25/8/2026 | 28/9/2026 | The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic number, revision, inode size and group counts, but never bounds s_log_block_size. On a successful verify,… | |
| Pendiente de análisis | Media (5.3) | 0.17% | — | Zephyr OSAI | 24/8/2026 | 26/8/2026 | The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security even before the application has called bt_has_register(). The service attribute pointers… | |
| Pendiente de análisis | Media (5.3) | 0.23% | — | Zephyr RtosAI | 24/8/2026 | 26/8/2026 | The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the first two words (res.data[0] and res.data[1]) and, before this fix, declared their result as an… | |
| Pendiente de análisis | Alta (8.8) | 0.22% | — | Zephyr VirtioAI | 24/8/2026 | 26/8/2026 | The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used->ring[idx].id is used directly as an index into vq->recv_cbs[] and vq->desc[], which are both allocated with exactly… | |
| Pendiente de análisis | Media (6.4) | 0.11% | — | Zephyr RtosAINXP Mailbox DriverAI | 24/8/2026 | 26/8/2026 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg * pointer to z_impl_mbox_send() and the underlying driver.… | |
| Pendiente de análisis | Media (5.3) | 0.14% | — | Zephyrproject ZephyrAI | 19/8/2026 | 26/8/2026 | The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into fixed 74-byte stack buffers and NUL-terminates them with buf[rc] = '\0', where rc is the return value of nvs_read(). Per its contract, nvs_read() returns the full stored entry length… | |
| Pendiente de análisis | Alta (8.1) | 0.31% | — | Zephyr OSAI | 19/8/2026 | 26/8/2026 | The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6CO, RFC 6775) carried inside ICMPv6 Router Advertisements. In handle_ra_6co() the 8-bit context_len field is taken directly from the packet and was never bounded to the RFC maximum of 128. The function computes… | |
| Pendiente de análisis | Alta (8.8) | 0.34% | — | Zephyrproject Hl7800 Modem DriverAI | 19/8/2026 | 26/8/2026 | The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-context dynamic parameters (local address, subnet mask, gateway, and DNS servers) that the cellular network assigns to the device. The response is linearized into a… | |
| Pendiente de análisis | Media (6.5) | 0.29% | — | Zephyrproject ZephyrAI | 18/8/2026 | 26/8/2026 | Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg->header.type_major_sdo_id & 0xF, range 0-15) and uses it to index the msg_size[] table. That table only defines entries up to PTP_MSG_MANAGEMENT… | |
| Pendiente de análisis | Media (6.5) | 0.15% | — | Zephyr KernelAI | 18/8/2026 | 26/8/2026 | The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c. Its default switch branch is the access-denied path, taken when k_object_validate() returns -EPERM (the calling user thread was never… | |
| Pendiente de análisis | Alta (8.8) | 0.14% | — | Zephyr RtosAI | 17/8/2026 | 26/8/2026 | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output buffer (K_SYSCALL_MEMORY_WRITE) and passed the two struct device *… | |
| Pendiente de análisis | Media (4.3) | 0.26% | — | Zephyrproject ZephyrAI | 17/8/2026 | 26/8/2026 | Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size() (subsys/net/ip/6lo.c). The destination inline size is looked up in da_inline_size_table, which has 13 entries, using an index built from the M, DAC and DAM bits of the received IPHC dispatch word… | |
| Pendiente de análisis | Alta (8.8) | 0.17% | — | Zephyrproject ZephyrAI | 14/8/2026 | 26/8/2026 | Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The cleanup switch handled only K_OBJ_MSGQ and K_OBJ_STACK; there was no K_OBJ_TIMER case. A… | |
| Pendiente de análisis | Media (5.8) | 0.13% | — | Zephyrproject ZephyrAI | 14/8/2026 | 26/8/2026 | A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout has been dequeued and its handler work_timeout() is in flight (blocked acquiring the work-queue spinlock), a concurrent cancellation does not wait for that… |