Zephyrproject
72 known vulnerabilities
Top Products
Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) cont
Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_
In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply
subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data
subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned s
In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the pac
On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain
Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_S
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi
A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/
An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati
The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using on
A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potenti
Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi
Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enable
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been re
The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; ove
Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver
dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cac
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local infor
Frequently Asked Questions
How many CVEs affect Zephyrproject?
Zephyrproject has 72 CVE records in our database, including 2 critical and 23 high severity vulnerabilities.
What are the most severe Zephyrproject vulnerabilities?
Zephyrproject has 2 critical severity (CVSS 9.0+) and 23 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Zephyrproject vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zephyrproject products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Zephyrproject Vulnerabilities
CyberStrike scans your infrastructure for Zephyrproject vulnerabilities and provides real-time remediation guidance.
Get Started