Vulnerabilidades em zephyrproject

61 resultados
Análise Vexday

O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.

CVE-2026-10634MEDIUMUse-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callbackEPSS 0.3%CVE-2026-10849HIGHHeap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response bodyEPSS 0.3%CVE-2026-10656MEDIUMNULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlersEPSS 0.3%CVE-2026-10675MEDIUMBluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)EPSS 0.2%CVE-2026-10664MEDIUMOut-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)EPSS 0.2%CVE-2026-10673HIGHOut-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassemblyEPSS 0.2%CVE-2026-10639MEDIUMUse-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`EPSS 0.2%CVE-2026-10644MEDIUMOut-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte bufferEPSS 0.2%CVE-2026-10642MEDIUMUnbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow controlEPSS 0.2%CVE-2026-10647MEDIUMDeadlock denial of service in USB CDC-NCM device class on TX enqueue failureEPSS 0.2%CVE-2026-10654LOWRFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth ClassicEPSS 0.2%CVE-2026-10848HIGHOut-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)EPSS 0.2%CVE-2026-10685HIGHUse-after-free of GATT subscribe params in Bluetooth host CCC-write response handlerEPSS 0.2%CVE-2026-10773MEDIUMOut-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)EPSS 0.2%CVE-2026-11368HIGHUse-after-free in Bluetooth host ATT TX completion on disconnect mid-transferEPSS 0.2%CVE-2026-10658HIGHOut-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validationEPSS 0.2%CVE-2026-10635MEDIUMDangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-initEPSS 0.2%CVE-2026-10663MEDIUMUse-after-free / double-free of the root USB device in the experimental USB host stackEPSS 0.2%CVE-2026-10668LOWHost-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driverEPSS 0.2%CVE-2026-10660MEDIUMShared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruptionEPSS 0.2%