Unpatched Zephyr OS Expose Devices to DoS Attacks via IP Spoofing
ID: 9c5a8c74-38fe-5691-aea5-38bb1279c828
STIX ID: report--9c5a8c74-38fe-5691-aea5-38bb1279c828
Feed Name: HackRead
Threat Score
Synopsys CyRC researchers disclosed flaws in the Zephyr OS network stack that allow externally received IP packets with spoofed source addresses (matching the host or destination) to be processed instead of dropped, enabling IP address spoofing that can bypass host IP-based access controls and cause loopback-triggered denial-of-service; affected Zephyr versions include 3.5, 3.4, and 2.7 (LTS), and patches have been merged into main and release branches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
