CVE-2026-1678Disclosure(zephyrproject / zephyr)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zephyrproject zephyr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null terminator can be written past the buffer. With assertions disabled (default), a malicious DNS response can trigger an out-of-bounds write when CONFIG_DNS_RESOLVER is enabled.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zephyr

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-05); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Products
zephyr

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-05: 4Mentions · 2026-03-09: 2Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-05: 4Technical Details · 2026-03-09: 1Technical Details · 2026-03-24: 103-0503-0903-24
Signal classification3 categories
Disclosure
571.4%
General
114.3%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-054
Disclosure4
2026-03-092
General1Patch1
2026-03-241
Disclosure1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.4 CVSS buffer overflow flaw (CVE-2026-1678) in Zephyr RTOS's DNS parser allows unauthenticated RCE on IoT devices. Patch immediately. #ZephyrRTOS #CVE20261678 #IoTSecurity #CyberSecurity #RCE #BufferOverflow #InfoSec #Vulnerability https://securityonline.info/critical-9-4-cvss-zephyr-rtos-flaw-exposes-millions-of-iot-devices-to-rce/ https://t.co/A0iS90gy56

    Post summary

    The tweet announces a critical buffer overflow flaw (CVE-2026-1678) in Zephyr RTOS that enables unauthenticated RCE on IoT devices and urges users to patch immediately.

    11043507
    10.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1678 DNS Resolver Buffer Overflow Vulnerability in Linux Kernel DNS Unpacking https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1678

    Post summary

    The text announces a buffer overflow vulnerability in the Linux kernel’s DNS resolver and links to a vulnerability database entry.

    0001274
    4.0K followersView on X
  • 0xkato@0xkato
    Disclosure

    The bounds check that forgot to keep checking CVE-2026-1678. https://www.0xkato.xyz/CVE-2026-1678-DNS-Parser-Overflow-in-Zephyr/

    Post summary

    The post references CVE‑2026‑1678 and highlights a missing bounds check that can lead to a DNS parser overflow in Zephyr, though it provides no PoC, exploit, or patch information.

    00010554
    1.1K followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall Another critical find! CVE-2026-1678 in Zephyr RTOS shows how IoT security challenges keep evolving. Appreciate you consistently sharing these important IoT security alerts. Track it now: https://vulntracker.io/cves/CVE-2026-1678

    Post summary

    The tweet highlights a new critical CVE in Zephyr RTOS and provides a link to a tracking page but offers no technical details, PoC, or evidence of exploitation.

    0000056
    394 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1678 - Critical dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null terminator can be wri... https://www.thehackerwire.com/vulnerability/CVE-2026-1678/ https://t.co/JKyeVtNhff

    Post summary

    A new critical DNS buffer overflow vulnerability, CVE-2026-1678, has been disclosed, detailing how dns_unpack_name() incorrectly caches buffer tailroom, but no PoC, exploit, or patch is provided.

    0000054
    124 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1678: CRITICAL] Vulnerability in dns_unpack_name() function can lead to out-of-bounds write in DNS resolver with assertions disabled. Stay cautious about cyber security risks.#cve,CVE-2026-1678,#cybersecurity https://cvefind.com/CVE-2026-1678

    Post summary

    The tweet announces CVE-2026-1678 as a critical out-of-bounds write in dns_unpack_name(), but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000071
    596 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1678 dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null t… https://www.cve.org/CVERecord?id=CVE-2026-1678

    Post summary

    The post outlines a newly disclosed vulnerability in dns_unpack_name, explaining how the cached buffer size becomes incorrect when the buffer grows.

    00000294
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSzephyrprojectzephyr---

Explore more