CVE-2026-19575 | Zephyr Project up to 4.4.2 Device Deinit kernel/device.c z_vrfy_device_deinit dev privileges management
A vulnerability classified as very critical has been found in Zephyr Project Zephyr up to 4.4.2. This impacts the function z_vrfy_device_deinit of the file kernel/device.c of the component Device Deinit Handler. Performing a manipulation of the argument dev results in improper privilege management.
This vulnerability was named CVE-2026-19575. The attack needs to be approached locally. There is no available exploit.
It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More