CVE-2026-10849 | ZephyrProject Zephyr up to 4.4.x hawkBit hawkbit.c response_json_cb body_frag_start/body_frag_len heap-based overflow

SecurityVulns

A vulnerability was found in ZephyrProject Zephyr up to 4.4.x. It has been classified as critical. This impacts the function response_json_cb of the file subsys/mgmt/hawkbit/hawkbit.c of the component hawkBit. The manipulation of the argument body_frag_start/body_frag_len leads to heap-based buffer overflow.

This vulnerability is documented as CVE-2026-10849. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More