Where
-Infinity
0

Nuvoton NuMaker HSUSBD USB device-controller driver (CONFIG_UDC_NUMAKER / udc_numaker.c)Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver

Risk 27
Severity
4.6
First published (updated )

Zephyr Project ZephyrStack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`

Risk 86
Severity
9.8
First published (updated )

Zephyr Project ZephyrSMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads

Risk 65
Severity
7.8
First published (updated )

nRF70 Wi-Fi driverOut-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)

Risk 39
Severity
5
First published (updated )

zephyrproject zephyrHeap buffer overflow on WireGuard receive path via unbounded incoming packet length

Risk 56
Severity
7.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zephyr Project ZephyrUse-after-free / double-free of the root USB device in the experimental USB host stack

Risk 46
Severity
6.1
First published (updated )

Zephyr Project ZephyrNULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume

Risk 28
Severity
4.7
First published (updated )

Zephyr Zephyr DNS resolver (CONFIG_MDNS_RESOLVER)Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)

Risk 27
Severity
5.3
First published (updated )

Runtime ZephyrNULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers

Risk 27
Severity
4.6
First published (updated )

ZephyrUse-after-free race in SNTP async client when closing the socket while the socket service is still polling it

Risk 45
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zephyr Bluetooth Classic RFCOMM host stackRFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic

Risk 17
Severity
3.1
First published (updated )

Zephyr net_buf libraryNon-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref

Risk 75
Severity
8.1
First published (updated )

Zephyr Bluetooth controller ISO Adaptation Layer (ISOAL)Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets

Risk 43
Severity
8.1
EPSS
0.31%
First published (updated )

Zephyr ProjectOut-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)

Risk 56
Severity
7.4
First published (updated )

zephyrproject zephyrNULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion

Risk 36
Severity
6.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zephyr HTTP serverPath traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read

Risk 43
Severity
7.5
First published (updated )

Zephyr net stackBroken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack

Risk 60
Severity
8.1
First published (updated )

Zephyr USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c)Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure

Risk 32
Severity
5.3
First published (updated )

Zephyr Project Zephyr Bluetooth LE Audio BAP unicast clientRemotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling

Risk 38
Severity
6.5
First published (updated )

ZephyrUse-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation

Risk 56
Severity
7.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microchip SERCOM-G1 (PIC32CM-JH) async UART driver (uart_mchp_sercom_g1.c)Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer

Risk 29
Severity
4.2
First published (updated )

Zephyr Project ZephyrOut-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)

Risk 68
Severity
8.7
First published (updated )

Zephyrnet: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets

Risk 43
Severity
7.5
First published (updated )

Zephyr Project Zephyr RTOSUnbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control

Risk 27
Severity
4.6
First published (updated )

Zephyr Project Zephyr Bluetooth HostOut-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation

Risk 48
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zephyr Project Zephyr RTOSOut-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)

Risk 48
Severity
7.1
First published (updated )

Zephyr Project Zephyr RTOSOut-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image

Risk 31
Severity
5.5
First published (updated )

zephyrproject zephyrOut-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)

Risk 48
Severity
7.1
First published (updated )

Zephyr ZephyrUse-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)

Risk 48
Severity
7.1
First published (updated )

Zephyr Project ZephyrUse-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`

Risk 32
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203