Zephyr
This hub aggregates every CVE we track for Zephyr, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
263
CVEs tracked
16
Critical
91
High
0
In CISA KEV
Severity distribution
MEDIUM134HIGH91LOW22CRITICAL16
Monthly trend
3
1
1
0
4
0
0
0
1
0
1
4
0
6
1
1
0
5
1
4
30
28
57
18
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Zephyr.
- CVE-2026-17054Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly5.3
- CVE-2026-15890AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization5.3
- CVE-2026-17052Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allows arbitrary supervisor-memory write from userspace7.8
- CVE-2026-17051Out-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound doorbell length6.0
- CVE-2026-17050Double free of the USB host configuration descriptor when device enumeration fails5.7
- CVE-2026-16515ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack4.7
- CVE-2026-16514Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved4.3
- CVE-2026-16512Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames3.1
- CVE-2026-14986Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transaction6.8
- CVE-2026-16148Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy delayable work item4.6
- CVE-2026-16147it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruption6.8
- CVE-2026-15924Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr sockets5.9
- CVE-2026-15893Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS6.5
- CVE-2026-15923Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_size4.6
- CVE-2026-15892Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service5.3
Product normalization is registry-driven with AI assist and human review. How it works