CVE-2026-11743 | Zephyr Project up to 4.4.1 Flash Driver flash_sf32lb_mpi_qspi_nor.c flash_read/flash_write offset/size signed conversion
A vulnerability has been found in Zephyr Project Zephyr up to 4.4.1 and classified as very critical. Impacted is the function flash_read/flash_write of the file drivers/flash/flash_sf32lb_mpi_qspi_nor.c of the component Flash Driver. Performing a manipulation of the argument offset/size results in signed to unsigned conversion error.
This vulnerability is reported as CVE-2026-11743. The attack requires a local approach. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More