Zephyr
Zephyr Rtos: vulnerabilidades y CVE
Zephyr Rtos tiene 19 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses19
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-17050 | Media (5.7) | 0.16% | — | 21 sept 2026 | The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three… |
| CVE-2026-16514 | Media (4.3) | 0.24% | — | 18 sept 2026 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken… |
| CVE-2026-16512 | Baja (3.1) | 0.17% | — | 18 sept 2026 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct… |
| CVE-2026-16148 | Media (4.6) | 0.17% | — | 14 sept 2026 | The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in… |
| CVE-2026-15924 | Media (5.9) | 0.31% | — | 14 sept 2026 | Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and… |
| CVE-2026-15893 | Media (6.5) | 0.20% | — | 14 sept 2026 | net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where… |
| CVE-2026-15892 | Media (5.3) | 0.27% | — | 13 sept 2026 | The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for… |
| CVE-2026-14697 | Media (6.5) | 0.18% | — | 31 ago 2026 | net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pending_queue is… |
| CVE-2026-14696 | Media (6.5) | 0.20% | — | 31 ago 2026 | When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface is handled. For… |
| CVE-2026-14367 | Baja (3.1) | 0.10% | — | 31 ago 2026 | The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchronization. The… |
| CVE-2026-13216 | Media (6.1) | 0.18% | — | 25 ago 2026 | The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI config… |
| CVE-2026-13343 | Media (5.3) | 0.23% | — | 24 ago 2026 | The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only… |
| CVE-2026-9728 | Media (6.4) | 0.11% | — | 24 ago 2026 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original,… |
| CVE-2026-9771 | Alta (8.8) | 0.14% | — | 17 ago 2026 | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the… |
| CVE-2026-12364 | Alta (8.4) | 0.16% | — | 14 ago 2026 | The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the… |
| CVE-2026-12234 | Alta (7.8) | 0.11% | — | 12 ago 2026 | The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(),… |
| CVE-2026-12233 | Media (5.9) | 0.51% | — | 12 ago 2026 | The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called… |
| CVE-2026-8718 | Alta (8.4) | 0.16% | — | 10 ago 2026 | tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid()… |
| CVE-2026-11812 | Baja (2.5) | 0.10% | — | 10 ago 2026 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.