CVE-2026-0849: Zephyrproject Zephyr

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack execution.

Affected products

Published 2026-03-16. Last modified 2026-06-17.