Vulnerabilidades em zephyrproject
71 resultadosAnálise Vexday
O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.
CVE-2026-10681MEDIUMSMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slotEPSS 0.1%CVE-2026-11985LOWCross-thread FPU register leak on ARM when FPU enabled without register sharingEPSS —CVE-2026-11894MEDIUMDouble-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error pathsEPSS —CVE-2026-12052MEDIUMOut-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the responseEPSS —CVE-2026-11812LOWUpdateHub: race condition on shared context causes out-of-bounds write and DoSEPSS —CVE-2026-8718HIGHOut-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLSEPSS —CVE-2026-11811LOWSocket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoSEPSS —CVE-2026-12051MEDIUMNULL pointer dereference in USB DFU device_next download handler (handle_download)EPSS —CVE-2026-11810HIGHNULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS)EPSS —CVE-2026-11809LOWUpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadataEPSS —CVE-2026-11893MEDIUMDouble free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb)EPSS —