CNNVD-202511-1166 Information

CNNVD ID

CNNVD-202511-1166

CVE-2025-9408

  • CNNVD Published: 2025-11-11

Description (Chinese)

Zephyr是Zephyr开源的一个可扩展的实时操作系统 (RTOS)。 Zephyr存在安全漏洞,该漏洞源于系统调用入口存在竞争条件,可能导致恶意用户空间进程进行权限提升。

Description (English)

Zephyr is an extended real-time operating system (RTOS) from Zephyr open source. Zephyr has a security loophole, which stems from competitive conditions at the system ’ s access point, which may lead to the increased authority of the malicious user space process.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Zephyr

Published

2025-11-11

Last Modified

2026-02-24

References

https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3r6j-5mp3-75wr

Patch

https://github.com/zephyrproject-rtos/zephyr/releases

Share on: