Zephyr Project
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 34 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 15, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal
Cross-thread FPU register leak on ARM when FPU enabled without register sharing
Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)
Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers
SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot
NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller
Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`
SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads
Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
Use-after-free / double-free of the root USB device in the experimental USB host stack
Monitor Zephyr Project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.