CVE-2024-11263: Zephyrproject Zephyr
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.
Affected products
- Zephyrproject Zephyr: up to and including 3.7.0
Published 2024-11-15. Last modified 2026-06-17.