CVE-2026-17054 | ZephyrProject Zephyr up to 4.4.1 ESP-hosted Wi-Fi driver drivers/wifi/esp_hosted esp_hosted_event_task data_length out-of-bounds

SecurityVulns

A vulnerability, which was classified as critical, was found in ZephyrProject Zephyr up to 4.4.1. Affected by this vulnerability is the function esp_hosted_event_task of the file drivers/wifi/esp_hosted of the component ESP-hosted Wi-Fi driver. Executing a manipulation of the argument data_length can lead to out-of-bounds read.

This vulnerability appears as CVE-2026-17054. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More