Zephyrproject
Zephyrproject Zephyr: vulnerabilities and CVEs
Zephyrproject Zephyr has 218 published vulnerabilities, 106 of them in the last 12 months. 28 are rated critical and 0 are listed by CISA as actively exploited.
CVEs218
Last 12 months106
Critical28
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17053 | Medium (4.4) | 0.09% | — | Oct 1, 2026 | The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev,… |
| CVE-2026-18746 | Medium (5.9) | 0.25% | — | Sep 28, 2026 | parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately… |
| CVE-2026-18417 | Medium (6.5) | 0.18% | — | Sep 28, 2026 | The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(),… |
| CVE-2026-18416 | Low (3.7) | 0.22% | — | Sep 28, 2026 | The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource path against the URI carried in a Uri-Query href= option. That URI is not NUL terminated, but the… |
| CVE-2026-18415 | Medium (6.3) | 0.10% | — | Sep 28, 2026 | ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with… |
| CVE-2026-18414 | High (7.8) | 0.12% | — | Sep 28, 2026 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure… |
| CVE-2026-18413 | High (7.8) | 0.12% | — | Sep 28, 2026 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure… |
| CVE-2026-16513 | High (7.8) | 0.11% | — | Sep 28, 2026 | The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle… |
| CVE-2026-15890 | Medium (5.3) | 0.06% | — | Sep 21, 2026 | The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in… |
| CVE-2026-17052 | High (7.8) | 0.12% | — | Sep 21, 2026 | The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and… |
| CVE-2026-16515 | Medium (4.7) | 0.20% | — | Sep 18, 2026 | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). It did not check whether the triggering… |
| CVE-2026-15923 | Medium (4.6) | 0.17% | — | Sep 14, 2026 | The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value… |
| CVE-2026-15460 | Medium (5.4) | 0.16% | — | Sep 9, 2026 | The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target… |
| CVE-2026-14368 | Medium (5.4) | 0.23% | — | Aug 31, 2026 | The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (string_length > buflen),… |
| CVE-2026-14366 | Medium (6.4) | 0.16% | — | Aug 31, 2026 | The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the net_pkt is owned by the L2/networking… |
| CVE-2026-13481 | Medium (5.4) | 0.26% | — | Aug 26, 2026 | The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In tlv_mgmt_post_recv(), the PTP_MGMT_TIME case casts mgmt_tlv->data to a 10-byte struct ptp_timestamp… |
| CVE-2026-13480 | Low (3.1) | 0.26% | — | Aug 26, 2026 | The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain… |
| CVE-2026-13479 | Medium (4.3) | 0.24% | — | Aug 26, 2026 | The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in… |
| CVE-2026-13217 | Medium (5.9) | 0.51% | — | Aug 25, 2026 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without… |
| CVE-2026-12634 | Medium (5.3) | 0.14% | — | Aug 19, 2026 | The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into fixed 74-byte stack buffers and NUL-terminates them with buf[rc] = '\0', where rc is the… |
| CVE-2026-12632 | Medium (6.5) | 0.29% | — | Aug 18, 2026 | Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg->header.type_major_sdo_id & 0xF, range 0-15)… |
| CVE-2026-12630 | Medium (4.3) | 0.26% | — | Aug 17, 2026 | Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size() (subsys/net/ip/6lo.c). The destination inline size is looked up in da_inline_size_table, which… |
| CVE-2026-12366 | High (8.8) | 0.17% | — | Aug 14, 2026 | Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup.… |
| CVE-2026-12365 | Medium (5.8) | 0.13% | — | Aug 14, 2026 | A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout has been dequeued and its handler work_timeout() is in… |
| CVE-2026-12232 | Medium (6.1) | 0.15% | — | Aug 12, 2026 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const… |
| CVE-2026-12052 | Medium (5.2) | 0.27% | — | Aug 11, 2026 | The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_parameters) and… |
| CVE-2026-12051 | Medium (4.6) | 0.23% | — | Aug 11, 2026 | The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes… |
| CVE-2026-11985 | Low (3.6) | 0.13% | — | Aug 11, 2026 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI permit the compiler to emit hardware FP… |
| CVE-2026-11742 | Low (3.6) | 0.13% | — | Aug 7, 2026 | The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued via k_queue_alloc_append/alloc_prepend, the data… |
| CVE-2026-11368 | Medium (6.5) | 0.30% | — | Aug 4, 2026 | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.