CVE-2026-15461Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 09/10/2026 Severity Medium CVE-2026-15460Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 09/09/2026 Severity Medium CVE-2026-14697IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/31/2026 Severity Medium CVE-2026-14696Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/31/2026 Severity Medium CVE-2026-14368Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser Exploitation status Public exploit Fix YesAffected product Z zephyr Published 08/31/2026 Severity Medium CVE-2026-14367I3C IBI work-node free-list data race between ISR and workqueue thread Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/31/2026 Severity Low CVE-2026-14366SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pkt Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/31/2026 Severity Medium CVE-2026-13735WireGuard keepalive transport-data messages accepted without Poly1305 authentication Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/28/2026 Severity Low CVE-2026-13734Zephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay endpoint hijack Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/28/2026 Severity Medium CVE-2026-13481Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/26/2026 Severity Medium CVE-2026-13480Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/26/2026 Severity Low CVE-2026-13479Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/26/2026 Severity Low CVE-2026-13478Out-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_count Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/25/2026 Severity Medium CVE-2026-13217NULL-pointer dereference in Zephyr OCPP CALLRESULT parsing via unchecked strtok_r/atoi Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/25/2026 Severity Medium CVE-2026-13216Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability length Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/25/2026 Severity Medium CVE-2026-13215Zephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a crafted filesystem image Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/25/2026 Severity Medium CVE-2026-13214Stack buffer overflow in OCPP GetConfiguration key parsing Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/25/2026 Severity Critical CVE-2026-13213Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_register Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/24/2026 Severity Medium CVE-2026-13212Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring descriptor id Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/24/2026 Severity High CVE-2026-13343Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/24/2026 Severity Medium CVE-2026-9728TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/24/2026 Severity Medium CVE-2026-12999Infineon Airoc Wi-Fi driver leaks TX buffers on send failure, leading to permanent pool exhaustion Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/22/2026 Severity Medium CVE-2026-12634Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read length Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/19/2026 Severity Medium CVE-2026-12522Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fields Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/19/2026 Severity High CVE-2026-12633Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router Advertisement Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/19/2026 Severity High CVE-2026-12632Out-of-bounds read in Zephyr PTP message parsing from unvalidated message type Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/18/2026 Severity Medium CVE-2026-12631Broken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr kernel Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/18/2026 Severity Medium CVE-2026-12520Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/18/2026 Severity Medium CVE-2026-12519Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/17/2026 Severity Medium CVE-2026-9771Missing device-pointer validation in flash_copy() syscall allows userspace privilege escalation Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/17/2026 Severity High CVE-2026-126306LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing mode Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/17/2026 Severity Medium CVE-2026-12629PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/17/2026 Severity Medium CVE-2026-12366Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/14/2026 Severity High CVE-2026-12365Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/14/2026 Severity Medium CVE-2026-12364Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/14/2026 Severity High CVE-2026-12363Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0 Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/14/2026 Severity Medium CVE-2026-12236Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/13/2026 Severity Medium CVE-2026-12235Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) Exploitation status Public exploit Fix YesAffected product Z zephyr Published 08/12/2026 Severity Medium CVE-2026-12234TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write Exploitation status Public exploit Fix YesAffected product Z zephyr Published 08/12/2026 Severity High CVE-2026-12233Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/12/2026 Severity Medium CVE-2026-12232Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/12/2026 Severity Medium CVE-2026-12052Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the response Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/11/2026 Severity Medium CVE-2026-12051NULL pointer dereference in USB DFU device_next download handler (handle_download) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/11/2026 Severity Medium CVE-2026-11894Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/11/2026 Severity Medium CVE-2026-11985Cross-thread FPU register leak on ARM when FPU enabled without register sharing Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/11/2026 Severity Low CVE-2026-11893Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/11/2026 Severity Medium CVE-2026-11812UpdateHub: race condition on shared context causes out-of-bounds write and DoS Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/10/2026 Severity Low CVE-2026-11811Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/10/2026 Severity Low CVE-2026-8718Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS Exploitation status Public exploit Fix YesAffected product Z zephyr Published 08/10/2026 Severity High CVE-2026-11809UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/10/2026 Severity Low CVE-2026-11810NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/10/2026 Severity High CVE-2026-11743Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/07/2026 Severity Medium CVE-2026-11742Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/07/2026 Severity Low CVE-2026-11368Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/04/2026 Severity High CVE-2026-10849Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/03/2026 Severity High CVE-2026-10848Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg) Exploitation status Public exploit Fix YesAffected product Z zephyr Published 08/02/2026 Severity High CVE-2026-10774PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/02/2026 Severity Low CVE-2026-10773Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) Exploitation status Public exploit Fix YesAffected product Z zephyr Published 08/01/2026 Severity Medium CVE-2026-2411Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 08/01/2026 Severity Medium CVE-2026-10686Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/31/2026 Severity Medium CVE-2026-10685Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/31/2026 Severity High CVE-2026-10684Out-of-bounds read in coredump shell when printing stored-dump target code Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/29/2026 Severity Low CVE-2026-10683DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/27/2026 Severity Low CVE-2026-10682Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/27/2026 Severity Medium CVE-2026-10681SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/25/2026 Severity Medium CVE-2026-7007Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/24/2026 Severity Medium CVE-2026-10680Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/21/2026 Severity High CVE-2026-10679Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/21/2026 Severity Low CVE-2026-10678NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/21/2026 Severity High CVE-2026-10677Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/21/2026 Severity Medium CVE-2026-10675Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/21/2026 Severity Medium CVE-2026-10674DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/21/2026 Severity Medium CVE-2026-10673Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly Exploitation status Public exploit Fix YesAffected product Z zephyr Published 07/15/2026 Severity High CVE-2026-10672Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) Exploitation status Public exploit Fix YesAffected product Z zephyr Published 07/14/2026 Severity High CVE-2026-10671User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/14/2026 Severity High CVE-2026-10670User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/14/2026 Severity Medium CVE-2026-10669Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/14/2026 Severity High CVE-2026-10668Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/12/2026 Severity Low CVE-2026-10667SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads Exploitation status Public exploit Fix YesAffected product Z zephyr Published 07/12/2026 Severity High CVE-2026-10666Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c` Exploitation status Public exploit Fix YesAffected product Z zephyr Published 07/12/2026 Severity High CVE-2026-10665Heap buffer overflow on WireGuard receive path via unbounded incoming packet length Exploitation status Public exploit Fix YesAffected product Z zephyr Published 07/12/2026 Severity High CVE-2026-10664Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count) Exploitation status Public exploit Fix YesAffected product Z zephyr Published 07/12/2026 Severity Medium CVE-2026-10663Use-after-free / double-free of the root USB device in the experimental USB host stack Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/12/2026 Severity Medium CVE-2026-10660Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/11/2026 Severity Medium CVE-2026-10659NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/07/2026 Severity Medium CVE-2026-10657Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/05/2026 Severity Low CVE-2026-10656NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 07/05/2026 Severity Medium CVE-2026-10655Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/30/2026 Severity Medium CVE-2026-10654RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/30/2026 Severity Low CVE-2026-10653Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/30/2026 Severity Medium CVE-2026-9263Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets Exploitation status Public exploit Fix YesAffected product Z zephyr Published 06/30/2026 Severity Medium CVE-2026-10652Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`) Exploitation status Public exploit Fix YesAffected product Z zephyr Published 06/30/2026 Severity Medium CVE-2026-10648NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/29/2026 Severity Medium CVE-2026-8023Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read Exploitation status Public exploit Fix YesAffected product Z zephyr Published 06/29/2026 Severity High CVE-2026-7656Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack Exploitation status Public exploit Fix YesAffected product Z zephyr Published 06/29/2026 Severity High CVE-2026-10647Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/29/2026 Severity Medium CVE-2026-10593Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/28/2026 Severity Medium CVE-2026-10646Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/28/2026 Severity High CVE-2026-10644Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/28/2026 Severity Medium CVE-2026-10643Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check) Exploitation status Not known exploited Fix YesAffected product Z zephyr Published 06/27/2026 Severity High