Zephyr
This hub aggregates every CVE we track for Zephyr, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
196
CVEs tracked
15
Critical
80
High
0
In CISA KEV
Severity distribution
MEDIUM88HIGH80CRITICAL15LOW13
Monthly trend
6
3
1
1
0
4
0
0
0
1
0
1
4
0
6
1
1
0
5
1
4
30
28
8
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Zephyr.
- CVE-2026-11743Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write6.6
- CVE-2026-11742Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock3.6
- CVE-2026-11368Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer7.1
- CVE-2026-10849Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body8.2
- CVE-2026-10848Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)7.0
- CVE-2026-10774PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS2.4
- CVE-2026-10773Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)5.4
- CVE-2026-2411Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values6.5
- CVE-2026-10686Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers5.8
- CVE-2026-10685Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler7.6
- CVE-2026-10684Out-of-bounds read in coredump shell when printing stored-dump target code3.0
- CVE-2026-10683DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)2.4
- CVE-2026-10682Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace6.6
- CVE-2026-10681SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot6.5
- CVE-2026-7007Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image4.6
Product normalization is registry-driven with AI assist and human review. How it works