7.3high
SecMateSECMATE-2025-0031
VendorZephyr Project
ProductZephyr
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
AdvisoryGHSA-qx3g-5g22-fq5w
Timeline
Published
Mar 27, 2026
Summary
The eswifi socket offload driver in Zephyr RTOS contains a buffer overflow vulnerability where user-provided payloads are copied into a fixed buffer without bounds checking. Oversized sends via eswifi_socket_send corrupt kernel memory, potentially leading to code execution or denial of service.