CVE-2026-1679
EUVD-2026-1690328.03.2026, 00:16
The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi->buf`, corrupting kernel memory (CWE-120). Exploit requires local code that can call the socket send API; no remote attacker can reach it directly.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zephyrproject | zephyr | 𝑥 ≤ 4.3.0 |
𝑥
= Vulnerable software versions