Zephyr Project
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 37 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 15, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS
Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path
Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability length
Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal
Cross-thread FPU register leak on ARM when FPU enabled without register sharing
Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)
Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers
SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot
NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller
Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`
Monitor Zephyr Project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.