CVE-2025-9408: Zephyrproject-Rtos Zephyr
High severity, CVSS 8.1. EPSS: 0.1% chance of exploitation in the next 30 days.
System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for malicious userspace processes.
Affected products
- Zephyrproject-Rtos Zephyr
Published 2025-11-11. Last modified 2026-06-17.