Vulnerabilities
Vulnerable Software
Zephyrproject:  >> Zephyr  >> 4.2.1  Security Vulnerabilities
The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi->buf`, corrupting kernel memory (CWE-120). Exploit requires local code that can call the socket send API; no remote attacker can reach it directly.
CVSS Score
7.3
EPSS Score
0.002
Published
2026-03-28
Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.
CVSS Score
6.1
EPSS Score
0.002
Published
2026-03-16
dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null terminator can be written past the buffer. With assertions disabled (default), a malicious DNS response can trigger an out-of-bounds write when CONFIG_DNS_RESOLVER is enabled.
CVSS Score
9.4
EPSS Score
0.004
Published
2026-03-05


Contact Us

Shodan ® - All rights reserved