Known Vulnerabilities for products from Zephyrproject
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Zephyrproject".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-13351 json | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number o... | Not Provided | 2026-06-25 | 2026-07-06 |
| CVE-2026-11368 json | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel vi... | Not Provided | 2026-08-04 | 2026-08-09 |
| CVE-2026-10849 json | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server i... | Not Provided | 2026-08-03 | 2026-08-09 |
| CVE-2026-10848 json | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) u... | Not Provided | 2026-08-02 | 2026-08-10 |
| CVE-2026-10774 json | Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth... | Not Provided | 2026-08-02 | 2026-08-10 |
| CVE-2026-10773 json | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char *... | Not Provided | 2026-08-01 | 2026-08-07 |
| CVE-2026-10686 json | Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branc... | Not Provided | 2026-07-31 | 2026-08-07 |
| CVE-2026-10685 json | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the ... | Not Provided | 2026-07-31 | 2026-08-07 |
| CVE-2026-10683 json | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler ga... | Not Provided | 2026-07-27 | 2026-08-12 |
| CVE-2026-10682 json | The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed... | Not Provided | 2026-07-27 | 2026-08-12 |
| CVE-2026-10681 json | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread pe... | Not Provided | 2026-07-25 | 2026-08-12 |
| CVE-2026-10680 json | The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/classic/l2... | Not Provided | 2026-07-21 | 2026-07-30 |
| CVE-2026-10679 json | The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config->freq... | Not Provided | 2026-07-21 | 2026-07-30 |
| CVE-2026-10678 json | The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes fr... | Not Provided | 2026-07-21 | 2026-07-30 |
| CVE-2026-10677 json | The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_po... | Not Provided | 2026-07-21 | 2026-07-30 |
| CVE-2026-10675 json | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the provi... | Not Provided | 2026-07-21 | 2026-07-30 |
| CVE-2026-10674 json | The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called L... | Not Provided | 2026-07-21 | 2026-07-30 |
| CVE-2026-10673 json | The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet f... | Not Provided | 2026-07-15 | 2026-08-17 |
| CVE-2026-10672 json | subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, siz... | Not Provided | 2026-07-14 | 2026-08-06 |
| CVE-2026-10670 json | The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thr... | Not Provided | 2026-07-14 | 2026-08-06 |