Executive brief
This security identifier was withdrawn because the underlying issue only existed in unreleased development code. It does not affect any public or production versions of the Zephyr operating system. There is no risk to customers or existing deployments, and no action is required.
Technical details
The Zephyr Project CNA rejected this CVE after determining that the vulnerable code path was never included in a formal release or stable branch. The defect was identified and addressed within unreleased development code. Because no production versions are impacted, the vulnerability is considered non-existent for the purposes of security tracking. No technical remediation is necessary for users of released Zephyr versions.
Affected products
- Zephyr Project Zephyr OS None (unreleased development code only)
Timeline
- 2026-06-18: disclosed: CVE record published and immediately marked as rejected