« Back to list

Zephyrproject

Zephyrproject Zephyr: vulnerabilities and CVEs

Zephyrproject Zephyr has 218 published vulnerabilities, 106 of them in the last 12 months. 28 are rated critical and 0 are listed by CISA as actively exploited.

CVEs218
Last 12 months106
Critical28
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-17053Medium (4.4)0.09%—Oct 1, 2026
The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev,…
CVE-2026-18746Medium (5.9)0.25%—Sep 28, 2026
parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately…
CVE-2026-18417Medium (6.5)0.18%—Sep 28, 2026
The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(),…
CVE-2026-18416Low (3.7)0.22%—Sep 28, 2026
The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource path against the URI carried in a Uri-Query href= option. That URI is not NUL terminated, but the…
CVE-2026-18415Medium (6.3)0.10%—Sep 28, 2026
ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with…
CVE-2026-18414High (7.8)0.12%—Sep 28, 2026
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure…
CVE-2026-18413High (7.8)0.12%—Sep 28, 2026
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure…
CVE-2026-16513High (7.8)0.11%—Sep 28, 2026
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle…
CVE-2026-15890Medium (5.3)0.06%—Sep 21, 2026
The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in…
CVE-2026-17052High (7.8)0.12%—Sep 21, 2026
The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and…
CVE-2026-16515Medium (4.7)0.20%—Sep 18, 2026
net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). It did not check whether the triggering…
CVE-2026-15923Medium (4.6)0.17%—Sep 14, 2026
The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value…
CVE-2026-15460Medium (5.4)0.16%—Sep 9, 2026
The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target…
CVE-2026-14368Medium (5.4)0.23%—Aug 31, 2026
The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (string_length > buflen),…
CVE-2026-14366Medium (6.4)0.16%—Aug 31, 2026
The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the net_pkt is owned by the L2/networking…
CVE-2026-13481Medium (5.4)0.26%—Aug 26, 2026
The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In tlv_mgmt_post_recv(), the PTP_MGMT_TIME case casts mgmt_tlv->data to a 10-byte struct ptp_timestamp…
CVE-2026-13480Low (3.1)0.26%—Aug 26, 2026
The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain…
CVE-2026-13479Medium (4.3)0.24%—Aug 26, 2026
The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in…
CVE-2026-13217Medium (5.9)0.51%—Aug 25, 2026
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without…
CVE-2026-12634Medium (5.3)0.14%—Aug 19, 2026
The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into fixed 74-byte stack buffers and NUL-terminates them with buf[rc] = '\0', where rc is the…
CVE-2026-12632Medium (6.5)0.29%—Aug 18, 2026
Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg->header.type_major_sdo_id & 0xF, range 0-15)…
CVE-2026-12630Medium (4.3)0.26%—Aug 17, 2026
Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size() (subsys/net/ip/6lo.c). The destination inline size is looked up in da_inline_size_table, which…
CVE-2026-12366High (8.8)0.17%—Aug 14, 2026
Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup.…
CVE-2026-12365Medium (5.8)0.13%—Aug 14, 2026
A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout has been dequeued and its handler work_timeout() is in…
CVE-2026-12232Medium (6.1)0.15%—Aug 12, 2026
The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const…
CVE-2026-12052Medium (5.2)0.27%—Aug 11, 2026
The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_parameters) and…
CVE-2026-12051Medium (4.6)0.23%—Aug 11, 2026
The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes…
CVE-2026-11985Low (3.6)0.13%—Aug 11, 2026
On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI permit the compiler to emit hardware FP…
CVE-2026-11742Low (3.6)0.13%—Aug 7, 2026
The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued via k_queue_alloc_append/alloc_prepend, the data…
CVE-2026-11368Medium (6.5)0.30%—Aug 4, 2026
The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1499.004 Application or System Exploitation21
  2. T1190 Exploit Public-Facing Application17
  3. T1068 Exploitation for Privilege Escalation16
  4. T1210 Exploitation of Remote Services15
  5. T1059 Command and Scripting Interpreter13
  6. T1005 Data from Local System6

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Zephyrproject