Known Vulnerabilities for Zephyr by Zephyrproject
Listed below are 10 of the newest known vulnerabilities associated with "Zephyr" by "Zephyrproject".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-13735 json | Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_data_me... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-13734 json | Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c validated... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-13478 json | The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passin... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-13351 json | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number o... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-13217 json | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-13216 json | The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In vi... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-13215 json | The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a file... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-13212 json | The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In ... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-12634 json | The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into ... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-12632 json | Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type... | Not Provided | 2026-08-18 | 2026-08-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zephyrproject | Zephyr | 2.3.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.3.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.2.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.2.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.2.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.2.0 | |||
| Application | Zephyrproject | Zephyr | 2.2.0 | |||
| Application | Zephyrproject | Zephyr | 2.1.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.1.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.0.0 | |||
| Application | Zephyrproject | Zephyr | 2.0.0 | |||
| Application | Zephyrproject | Zephyr | 2.0.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.0.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.0.0 | |||
| Application | Zephyrproject | Zephyr | 2.0.0 | |||
| Application | Zephyrproject | Zephyr | 2.0.0 | |||
| Operating System | Zephyrproject | Zephyr | 2.0.0 | |||
| Application | Zephyrproject | Zephyr | 1.9.2 | |||
| Operating System | Zephyrproject | Zephyr | 1.9.2 | |||
| Operating System | Zephyrproject | Zephyr | 1.9.1 |