Threats Tagged 'cve-2026-12634'
View all threats tagged with 'cve-2026-12634'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-12634'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-12634 is a medium-severity vulnerability in the Zephyr project's settings subsystem. It involves an out-of-bounds write of a single NUL byte past a fixed 74-byte stack buffer when reading stored setting-name entries from flash memory. This occurs because the nvs_read() function returns the full stored entry length, which can exceed the buffer size, and this length is used directly as the NUL terminator index without proper bounds checking. Exploitation requires an attacker with the ability to write directly to the flash backing the settings partition, such as a co-resident or untrusted component or physical access. The impact is limited to denial of service or crash due to stack corruption; there is no confidentiality impact and no network exposure via the normal settings API. The vulnerability affects Zephyr versions from 2.0.0 up to but not including 4.5.0. The fix involves skipping entries whose length exceeds the buffer size before writing the NUL terminator. Join the discussion | CVE Database V5 | 08/19/2026, 20:37:36 UTC Added: 08/19/2026, 20:52:41 UTC |
Showing 1 to 1 of 1 result