CVE-2026-0849
EUVD-2026-1218616.03.2026, 14:18
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack execution.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zephyrproject | zephyr | 4.3.0 |
| zephyrproject | zephyr | 4.3.0:rc1 |
| zephyrproject | zephyr | 4.3.0:rc2 |
| zephyrproject | zephyr | 4.3.0:rc3 |
𝑥
= Vulnerable software versions