Zephyr vulnerabilities
11 CVEs tracked
Zephyr RTOS appears in our reports primarily with critical vulnerabilities at the real-time operating system level. Key themes include race conditions on SMP systems (CVE-2026-10681), security bypasses in Bluetooth Mesh and GATT subsystems (CVE-2026-10675, CVE-2026-10685, CVE-2026-2411), improper kernel object cleanup (CVE-2026-12366), and memory corruption risks in USB DFU and ARM FPU contexts (CVE-2026-12051, CVE-2026-11985). Listed CVEs specifically include CVE-2026-10678 (MCTP validation) and CVE-2026-12630 (6LoWPAN out-of-bounds read). Defenders should pay special attention to userspace dynamic objects on SMP-configured systems, active Bluetooth provisioners, and ARM hard-FPU configurations.
Azərbaycanca: Zephyr RTOS hesabatlarımızda əsasən real-vaxt əməliyyat sistemi səviyyəsində kritik zəifliklərlə bağlı görünür. Əsas mövzular SMP sistemlərində rəqabət şəraiti (CVE-2026-10681), Bluetooth Mesh və GATT altsistemlərində təhlükəsizlik bypassları (CVE-2026-10675, CVE-2026-10685, CVE-2026-2411), kernel obyektlərinin düzgün təmizlənməməsi (CVE-2026-12366), eləcə də USB DFU və ARM FPU kontekstində yaddaş korrupsiyası riskləridir (CVE-2026-12051, CVE-2026-11985). Sadalanan CVE-lərə xüsusilə CVE-2026-10678 (MCTP validasiyası), CVE-2026-12630 (6LoWPAN oxuma kənarı) daxildir. Müdafiəçilər SMP konfiqurasiyalı sistemlərdə istifadəçi məkanı dinamik obyektlərinə, Bluetooth aktiv provayderlərinə və ARM hard-FPU konfiqurasiyalarına xüsusi diqqət yetirməlidir.
This vendor's CVEs11
This hub is built from skopnix's own reporting on Zephyr: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.