← Back

Zephyrproject

zephyrproject

189 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Zephyr
zephyr

CVEs (189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zephyrproject
1Zephyr
Jun 17, 2026
Aug 12, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Potential buffer overflow vulnerabilities in the following locations: https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blo...Show more
Potential buffer overflow vulnerabilities in the following locations: https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blob/main/subsys/usb/device/class/netusb/function_rndis... https://github.com/zephyrproject-rtos/zephyr/blob/main/subsys/usb/device/class/netusb/function_rndis.c#L841Show less
1Zephyrproject
1Zephyr
Jun 17, 2026
Jul 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jul 10, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
The bluetooth HCI host layer logic not clearing a global reference to a state pointer after handling connection events may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, lead...Show more
The bluetooth HCI host layer logic not clearing a global reference to a state pointer after handling connection events may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host layer.Show less
1Zephyrproject
1Zephyr
Jun 17, 2026
Jul 10, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
The bluetooth HCI host layer logic not clearing a global reference to a semaphore after synchronously sending HCI commands may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer,...Show more
The bluetooth HCI host layer logic not clearing a global reference to a semaphore after synchronously sending HCI commands may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host layer. Show less
1Zephyrproject
1Zephyr
Jun 17, 2026
Jul 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A missing nullptr-check in handle_ra_input can cause a nullptr-deref.
1Zephyrproject
1Zephyr
Jun 17, 2026
May 30, 2023
N/A· v4
7.7 HIGH· v3
N/A· v2
At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further exploitation is possible.
1Zephyrproject
1Zephyr
Jun 17, 2026
Feb 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
1Zephyrproject
1Zephyr
Jun 17, 2026
Jan 25, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jan 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jan 19, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_complete.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jan 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jan 11, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means the unencrypted firmware can be retrieved easily.
1Zephyrproject
1Zephyr
Jun 17, 2026
Dec 9, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.
1Zephyrproject
1Zephyr
Jun 17, 2026
Oct 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vulnerable node. The frame must have a CAN ID matching an installed filter in the vulnerable node (this...Show more
The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vulnerable node. The frame must have a CAN ID matching an installed filter in the vulnerable node (this can easily be guessed based on CAN traffic analyses). The frame must contain the opposite RTR bit as what the filter installed in the vulnerable node contains (if the filter matches RTR frames, the frame must be a data frame or vice versa).Show less
1Zephyrproject
1Zephyr
Jun 17, 2026
Aug 31, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-bounds write a byte zero.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jul 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jul 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.
1Zephyrproject
1Zephyr
Jun 17, 2026
Jun 28, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rq...Show more
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqhShow less
1Zephyrproject
1Zephyr
Jun 17, 2026
Jun 28, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6r...Show more
Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6rfp-cfrmShow less
1Zephyrproject
1Zephyr
Jun 17, 2026
Jun 28, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/sec...Show more
Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrpShow less