Vulnerabilidades em zephyrproject

71 resultados
Análise Vexday

O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.

CVE-2026-7007MEDIUMDivision by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem imageEPSS 0.2%CVE-2026-10667HIGHSMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threadsEPSS 0.2%CVE-2026-10774LOWPSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoSEPSS 0.2%CVE-2026-10645MEDIUMOut-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem imageEPSS 0.2%CVE-2026-10648MEDIUMNULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustionEPSS 0.1%CVE-2026-10683LOWDesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)EPSS 0.1%CVE-2026-10659MEDIUMNULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resumeEPSS 0.1%CVE-2026-10679LOWDivide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)EPSS 0.1%CVE-2026-10643HIGHOut-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)EPSS 0.1%CVE-2026-2411MEDIUMBluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic valuesEPSS 0.1%CVE-2026-10669HIGHXtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validationEPSS 0.1%CVE-2026-10680HIGHOut-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflowEPSS 0.1%CVE-2026-10671HIGHUser thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)EPSS 0.1%CVE-2026-10674MEDIUMDoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabledEPSS 0.1%CVE-2026-10677MEDIUMKernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource poolEPSS 0.1%CVE-2026-11743MEDIUMMissing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and writeEPSS 0.1%CVE-2026-10670MEDIUMUser-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifierEPSS 0.1%CVE-2026-10682MEDIUMOut-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspaceEPSS 0.1%CVE-2026-10684LOWOut-of-bounds read in coredump shell when printing stored-dump target codeEPSS 0.1%CVE-2026-11742LOWUse-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlockEPSS 0.1%