logo

Unpatched Zephyr OS Expose Devices to DoS Attacks via IP Spoofing

ID: 9c5a8c74-38fe-5691-aea5-38bb1279c828

STIX ID: report--9c5a8c74-38fe-5691-aea5-38bb1279c828

Feed Name: HackRead

Threat Score
60/100

Date Published: 2024-03-21

Date Updated: 2026-04-22

Author: Waqas

...
...

Synopsys CyRC researchers disclosed flaws in the Zephyr OS network stack that allow externally received IP packets with spoofed source addresses (matching the host or destination) to be processed instead of dropped, enabling IP address spoofing that can bypass host IP-based access controls and cause loopback-triggered denial-of-service; affected Zephyr versions include 3.5, 3.4, and 2.7 (LTS), and patches have been merged into main and release branches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.