Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.16% | — | Zephyr RtosAI | 14/8/2026 | 26/8/2026 | The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode implementation z_impl_z_log_msg_static_create() without performing any of the mandatory… | |
| Pendiente de análisis | Media (6.5) | 0.16% | — | Zephyr OSAI | 13/8/2026 | 26/8/2026 | The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_CHAR_DESC discovery. The per-entry stride rsp->len is taken directly from the peer's PDU, and the parse loop both tests… | |
| Pendiente de análisis | Media (6.3) | 0.13% | — | Zephyr LlextAI | 12/8/2026 | 26/8/2026 | The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (partially-linked) ELF extension. In llext_link_plt() (subsys/llext/llext_link.c), the relocatable branch (tgt != NULL, the path used for Xtensa relocatable objects) computed the patch address as… | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Zephyr RtosAI | 12/8/2026 | 26/8/2026 | The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-live user struct for subsequent decisions. The kernel iovec shadow buffer… | |
| Pendiente de análisis | Media (5.9) | 0.51% | — | Zephyr RtosAI | 12/8/2026 | 26/8/2026 | The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it. A statically zero-filled k_mutex has an uninitialized wait queue (its dlist… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Intel ALH Digital Audio Interface DriverAIZephyrproject ZephyrAI | 12/8/2026 | 26/8/2026 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const uint8_t alh_handshake_map[64] array and scales a FIFO register address, so an out-of-range stream_id… | |
| Pendiente de análisis | Media (5.2) | 0.27% | — | Zephyr USB Device StackAIZephyrproject ZephyrAI | 11/8/2026 | 26/8/2026 | The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_parameters) and GET_NTB_INPUT_SIZE (8-byte struct ntb_input_size) class requests and copies the whole structure into the… | |
| Pendiente de análisis | Media (4.6) | 0.23% | — | Zephyrproject ZephyrAI | 11/8/2026 | 1/9/2026 | The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, buf->len) and passes buf->data to the image write callback without checking that the… | |
| Pendiente de análisis | Baja (3.6) | 0.13% | — | Zephyrproject ZephyrAI | 11/8/2026 | 1/9/2026 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI permit the compiler to emit hardware FP instructions in any function, even code that never uses floating-point types. However, the callee-saved FP… | |
| Pendiente de análisis | Alta (8.4) | 0.16% | — | Zephyr RtosAI | 10/8/2026 | 26/8/2026 | tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes.… | |
| Pendiente de análisis | Baja (2.5) | 0.10% | — | Zephyr RtosAI | 10/8/2026 | 1/9/2026 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds[1]. Access to ctx was not serialized, and prepare_fds() wrote… | |
| Pendiente de análisis | Baja (3.7) | 0.40% | — | Zephyr UpdatehubAI | 10/8/2026 | 26/8/2026 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Zephyr UpdatehubAI | 10/8/2026 | 26/8/2026 | The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the outer array length (objects_len != 2) and then dereferences… | |
| Pendiente de análisis | Baja (3.7) | 0.35% | — | Zephyr UpdatehubAI | 10/8/2026 | 26/8/2026 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a heap buffer (metadata) that is correctly NUL-terminated, but a second buffer (metadata_copy) is allocated with… | |
| Pendiente de análisis | Baja (3.6) | 0.13% | — | Zephyrproject ZephyrAI | 7/8/2026 | 26/8/2026 | The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued via k_queue_alloc_append/alloc_prepend, the data pointer of an internally allocated alloc_node struct. The implementations of… | |
| Analizada | Media (6.5) | 0.30% | — | Zephyrproject Zephyr | 4/8/2026 | 1/9/2026 | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the completion handling to the system workqueue… | |
| Analizada | Alta (7.5) | 0.51% | — | Zephyrproject Zephyr | 3/8/2026 | 1/9/2026 | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response… | |
| Analizada | Alta (8.6) | 0.38% | — | Zephyrproject Zephyr | 2/8/2026 | 1/9/2026 | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1, outlen - 1) and then scanned the result with strchr(out_buf,… | |
| Analizada | Media (6.5) | 0.29% | — | Zephyrproject Zephyr | 2/8/2026 | 1/9/2026 | Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching… | |
| Analizada | Media (6.5) | 0.18% | — | Zephyrproject Zephyr | 1/8/2026 | 1/9/2026 | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Characteristic Value attribute that carries the application-specified security permissions (e.g. BT_GATT_PERM_READ_ENCRYPT / READ_AUTHEN /… | |
| Analizada | Media (5.4) | 0.27% | — | Zephyrproject Zephyr | 1/8/2026 | 1/9/2026 | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. The guard used msg_type <= sizeof(name) instead of msg_type <= ARRAY_SIZE(name); sizeof returns the byte size of the pointer array (32 on 32-bit, 64 on… | |
| Rechazada | Sin puntuar | — | — | Zephyrproject ZephyrAI | 1/8/2026 | 1/8/2026 | Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by CVE-2026-2411, which was assigned earlier for the same defect: the Bluetooth GATT notify/indicate paths check the permissions of the Characteristic Declaration… | |
| Analizada | Alta (7.5) | 0.52% | — | Zephyrproject Zephyr | 31/7/2026 | 7/8/2026 | Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-route path (net_route_packet()) and the on-link cross-interface path (net_route_packet_if()). Each set the packet… | |
| Analizada | Alta (7.6) | 0.30% | — | Zephyrproject Zephyr | 31/7/2026 | 1/9/2026 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback with NULL data is the documented signal… | |
| Pendiente de análisis | Baja (3) | 0.14% | — | Zephyrproject ZephyrAI | 29/7/2026 | 1/9/2026 | In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump header directly as an index into coredump_target_code2str[], a fixed 7-element array of string pointers, with no bounds check. A stored coredump whose tgt_code is >= 7 causes an out-of-bounds read… |