Executive brief
This security identifier was withdrawn because the identified defect does not exist in any released version of the Zephyr operating system. The issue was found only in unreleased development code and was corrected before reaching any production or stable releases. There is no risk to users of the software and no action is required.
Technical details
The Zephyr Project CNA rejected this CVE after determining that the defect was only present in unreleased development code. On all supported release branches, the affected value is corrected before it is used, making the vulnerability unreachable. Because the change that would have exposed the defect never transitioned from development to a released version, no stable builds are impacted. The identifier has been officially withdrawn.
Affected products
- Zephyr Project Zephyr OS None (unreleased development code only)
Timeline
- 2026-06-11: disclosed: CVE record received from Zephyr Project
- 2026-06-11: other: CVE rejected and withdrawn by Zephyr Project CNA