Zephyr
This hub aggregates every CVE we track for Zephyr, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
245
CVEs tracked
16
Critical
89
High
0
In CISA KEV
Severity distribution
MEDIUM119HIGH89LOW21CRITICAL16
Monthly trend
3
1
1
0
4
0
0
0
1
0
1
4
0
6
1
1
0
5
1
4
30
28
57
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Zephyr.
- CVE-2026-14697IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service6.5
- CVE-2026-14696Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion6.5
- CVE-2026-14368Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser5.4
- CVE-2026-14367I3C IBI work-node free-list data race between ISR and workqueue thread3.1
- CVE-2026-14366SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pkt6.4
- CVE-2026-13735WireGuard keepalive transport-data messages accepted without Poly1305 authentication3.7
- CVE-2026-13734Zephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay endpoint hijack6.5
- CVE-2026-13481Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP5.4
- CVE-2026-13480Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler3.1
- CVE-2026-13479Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler3.1
- CVE-2026-13478Out-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_count5.5
- CVE-2026-13217NULL-pointer dereference in Zephyr OCPP CALLRESULT parsing via unchecked strtok_r/atoi5.9
- CVE-2026-13216Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability length6.1
- CVE-2026-13215Zephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a crafted filesystem image6.8
- CVE-2026-13214Stack buffer overflow in OCPP GetConfiguration key parsing9.8
Product normalization is registry-driven with AI assist and human review. How it works