Zephyr
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 18, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace
Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow
Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool
Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)
DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled
Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation
Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion
Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)
Monitor Zephyr in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.