CVE-2026-0849: Zephyrproject Zephyr
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack execution.
Affected products
- Zephyrproject Zephyr: version 4.3.0 only
Published 2026-03-16. Last modified 2026-06-17.