Vulnerabilities in zephyrproject

61 results
Vexday analysis

O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.

CVE-2026-8023HIGHPath traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file readEPSS 0.9%CVE-2026-10666HIGHStack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`EPSS 0.5%CVE-2026-10665HIGHHeap buffer overflow on WireGuard receive path via unbounded incoming packet lengthEPSS 0.4%CVE-2026-10672HIGHUnterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)EPSS 0.4%CVE-2026-10640MEDIUMUse-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)EPSS 0.4%CVE-2026-10638MEDIUMUse-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or errorEPSS 0.4%CVE-2026-10678HIGHNULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controllerEPSS 0.3%CVE-2026-10646HIGHUse-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellationEPSS 0.3%CVE-2026-9263MEDIUMOut-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packetsEPSS 0.3%CVE-2026-7656HIGHBroken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stackEPSS 0.3%CVE-2026-10652MEDIUMOut-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)EPSS 0.3%CVE-2026-10636LOWUse-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)EPSS 0.3%CVE-2026-10655MEDIUMUse-after-free race in SNTP async client when closing the socket while the socket service is still polling itEPSS 0.3%CVE-2026-10637MEDIUMUse-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD QueryEPSS 0.3%CVE-2026-10686MEDIUMMissing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routersEPSS 0.3%CVE-2026-10657LOWOut-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)EPSS 0.3%CVE-2026-10593MEDIUMRemotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handlingEPSS 0.3%CVE-2026-10641HIGHOut-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)EPSS 0.3%CVE-2026-10651HIGHOut-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)EPSS 0.3%CVE-2026-10653MEDIUMNon-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unrefEPSS 0.3%