Releases: zephyrproject-rtos/zephyr
Release list
Zephyr 4.4.2
This is a bugfix release for Zephyr 4.4.1.
Security Vulnerability Related
- CVE-2026-7007 Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image
- CVE-2026-8023 Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read
- CVE-2026-9728 Under embargo until 2026-08-23
- CVE-2026-9771 Under embargo until 2026-08-16
- CVE-2026-10593 Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
- CVE-2026-10635 Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init
- CVE-2026-10641 Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)
- CVE-2026-10642 Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control
- CVE-2026-10643 Out-of-bounds heap write in Zephyr
recvmsg()ancillary-data path (insert_pktinfoundersizes the control-buffer capacity check) - CVE-2026-10644 Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer
- CVE-2026-10646 Use-after-return in
zsock_getaddrinfo()when a timed-out DNS query is retried without cancellation - CVE-2026-10647 Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
- CVE-2026-10651 Out-of-bounds read in Bluetooth Classic SDP attribute parsing (
bt_sdp_parse_attribute) - CVE-2026-10653 Non-atomic
net_bufreference counts cause double-free / free-list corruption under concurrent unref - CVE-2026-10654 RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic
- CVE-2026-10655 Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
- CVE-2026-10657 Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
- CVE-2026-10658 Out-of-bounds access in Bluetooth ISO receive (
bt_iso_recv) due to missing SDU-header length validation - CVE-2026-10659 NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume
- CVE-2026-10660 Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption
- CVE-2026-10663 Use-after-free / double-free of the root USB device in the experimental USB host stack
- CVE-2026-10665 Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
- CVE-2026-10667 SMP use-after-free in Zephyr
CONFIG_USERSPACEdynamic kernel-object tracking, reachable from unprivileged user threads - CVE-2026-10668 Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
- CVE-2026-10670 User-triggerable kernel NULL-pointer dereference (DoS) in
k_thread_name_copy()syscall verifier - CVE-2026-10671 User thread can re-initialize an in-use
k_pipe, corrupting kernel wait queues (CONFIG_USERSPACE) - CVE-2026-10674 DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled
- CVE-2026-10675 Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)
- CVE-2026-10677 Kernel heap memory leak in
z_vrfy_k_poll()lets an unprivileged user thread exhaust the kernel resource pool - CVE-2026-10678 NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller
- CVE-2026-10679 Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)
- CVE-2026-10680 Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via
uint16_tlength underflow - CVE-2026-10681 SMP race in
thread_idx_alloc()lets concurrentk_object_alloc(K_OBJ_THREAD)callers share a kernel-object permission slot - CVE-2026-10682 Out-of-bounds write in Zephyr
log_filter_setsyscall verifier reachable from userspace - CVE-2026-10683 DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)
- CVE-2026-10685 Under embargo until 2026-07-31
- CVE-2026-10686 Under embargo until 2026-07-31
- CVE-2026-10772 Under embargo until 2026-08-01
- CVE-2026-10773 Under embargo until 2026-08-01
- CVE-2026-10774 Under embargo until 2026-08-02
- CVE-2026-10848 Under embargo until 2026-08-02
- CVE-2026-10849 Under embargo until 2026-08-03
- CVE-2026-11368 Under embargo until 2026-08-04
- CVE-2026-11742 Under embargo until 2026-08-07
- CVE-2026-11743 Under embargo until 2026-08-07
- CVE-2026-11809 Under embargo until 2026-08-08
- CVE-2026-11810 Under embargo until 2026-08-08
- CVE-2026-11811 Under embargo until 2026-08-08
- CVE-2026-11812 Under embargo until 2026-08-08
- CVE-2026-11893 Under embargo until 2026-08-09
- CVE-2026-11894 Under embargo until 2026-08-09
- CVE-2026-11985 Under embargo until 2026-08-09
- CVE-2026-12051 Under embargo until 2026-08-10
- CVE-2026-12052 Under embargo until 2026-08-10
- CVE-2026-12233 Under embargo until 2026-08-11
- CVE-2026-12234 Under embargo until 2026-08-11
- CVE-2026-12236 Under embargo until 2026-08-13
- CVE-2026-12364 Under embargo until 2026-08-14
- CVE-2026-12519 Under embargo until 2026-08-16
- CVE-2026-12520 Under embargo until 2026-08-16
- CVE-2026-12521 Under embargo until 2026-08-16
- CVE-2026-12522 Under embargo until 2026-08-16
- CVE-2026-12629 Under embargo until 2026-08-16
- CVE-2026-12630 Under embargo until 2026-08-16
- CVE-2026-12631 Under embargo until 2026-08-16
- CVE-2026-12632 Under embargo until 2026-08-16
- CVE-2026-12633 Under embargo until 2026-08-16
- CVE-2026-12999 Under embargo until 2026-08-22
- CVE-2026-13213 Under embargo until 2026-08-23
- CVE-2026-13214 Under embargo until 2026-08-23
- CVE-2026-13215 Under embargo until 2026-08-23
- CVE-2026-13217 Under embargo until 2026-08-23
- CVE-2026-13478 Under embargo until 2026-08-25
- CVE-2026-13479 Under embargo until 2026-08-26
- CVE-2026-13480 Under embargo until 2026-08-26
- CVE-2026-13481 Under embargo until 2026-08-26
- [CVE-2026-13734](h...
Zephyr LTS v3.7.3-rc1
This is an LTS maintenance release with fixes.
Security Vulnerability Related
The following CVEs are addressed by this release:
More detailed information can be found in: https://docs.zephyrproject.org/latest/security/vulnerabilities.html
- CVE-2026-2411 — Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values (Impacts: >= 2.6.0, <= 4.4.1)
- CVE-2026-7007 — Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image (Impacts: >= 3.5.0, <= 4.4.1)
- CVE-2026-7656 — Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack (Impacts: <= 4.4.0)
- CVE-2026-8718 — Under embargo until 2026-08-08
- CVE-2026-9263 — Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets (Impacts: >= 3.3.0, <= 4.4.1)
- CVE-2026-9728 — Under embargo until 2026-08-23
- CVE-2026-10634 — Use-after-free in Zephyr native TCP net_tcp_foreach() due to dropping tcp_lock during the callback (Impacts: >= 3.6.0, <= 4.4.1)
- CVE-2026-10636 — Use-after-free in Zephyr IPv4 IGMP send path (igmp_send) (Impacts: >= 2.6.0, <= 4.4.1)
- CVE-2026-10637 — Use-after-free of net_pkt in IPv6 MLD send path triggerable by a link-local MLD Query (Impacts: >= 1.12.0, <= 4.4.0)
- CVE-2026-10638 — Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10639 — Use-after-free reading net_pkt_iface() of a sent ICMPv4 echo-reply packet in icmpv4_handle_echo_request() (Impacts: >= 4.2.0, <= 4.4.1)
- CVE-2026-10640 — Use-after-free reading net_pkt iface after send in IPv6 Neighbor Discovery (ipv6_nbr.c) (Impacts: >= 3.3.0, <= 4.4.1)
- CVE-2026-10641 — Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values) (Impacts: >= 3.7.0)
- CVE-2026-10643 — Out-of-bounds heap write in Zephyr recvmsg() ancillary-data path (insert_pktinfo undersizes the control-buffer capacity check) (Impacts: >= 4.0.0, <= 4.4.1)
- CVE-2026-10645 — Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image (Impacts: <= 4.4)
- CVE-2026-10652 — Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated rdlength) (Impacts: >= 4.3.0, <= 4.4.1)
- CVE-2026-10654 — RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic (Impacts: >= 1.6.0, <= 4.4.0)
- CVE-2026-10657 — Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL) (Impacts: >= 1.10.0, <= 4.4.1)
- CVE-2026-10658 — Out-of-bounds access in Bluetooth ISO receive (bt_iso_recv) due to missing SDU-header length validation (Impacts: <= 4.4.0)
- CVE-2026-10660 — Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption (Impacts: >= 3.6.0, <= 4.4.0)
- CVE-2026-10666 — Stack buffer overflow in net_ipaddr_parse() IPv4 address-with-port parsing in subsys/net/ip/utils.c (Impacts: >1.10.0)
- CVE-2026-10667 — SMP use-after-free in Zephyr CONFIG_USERSPACE dynamic kernel-object tracking, reachable from unprivileged user threads (Impacts: <= 4.3)
- CVE-2026-10669 — Xtensa MPU arch_buffer_validate() integer-overflow lets a user thread bypass syscall pointer validation (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10670 — User-triggerable kernel NULL-pointer dereference (DoS) in k_thread_name_copy() syscall verifier (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10672 — Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) (Impacts: v4.3.0, v4.2.1, v3.7.1)
- CVE-2026-10673 — Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10674 — DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10675 — Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS) (Impacts: >= 3.5.0, <= 4.4.1)
- CVE-2026-10677 — Kernel heap memory leak in z_vrfy_k_poll() lets an unprivileged user thread exhaust the kernel resource pool (Impacts: >= 1.12.0, <= 4.4.1)
- CVE-2026-10679 — Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) (Impacts: >= 1.8.0, <= 4.4.1)
- CVE-2026-10680 — Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via uint16_t length underflow (Impacts: >= 4.2.0, < 4.3.1; >= 4.4.0, <= 4.4.1)
- CVE-2026-10681 — SMP race in thread_idx_alloc() lets concurrent k_object_alloc(K_OBJ_THREAD) callers share a kernel-object permission slot (Impacts: >= 2.0.0, <= 4.4.1)
- CVE-2026-10682 — Out-of-bounds write in Zephyr log_filter_set syscall verifier reachable from userspace (Impacts: >= 3.0.0, <= 4.4.1)
- CVE-2026-10685 — Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler (Impacts: >= 2.4.0, <= 4.4.1)
- CVE-2026-10686 — [Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet l...
Zephyr v4.4.2-rc1
Issues fixed
These GitHub issues were addressed since the previous 4.4.1 tagged release:
- #103831 - Add mcxc242 lpuart dma support (async api)
- #104900 - Bluetooth LE host qualification for 4.4 release
- #104922 - drivers: nuvoton: hs usbd: control cmds stuck naking
- #106334 - Thread-safety race condition in net_buf_unref
- #107374 - ESP32 S3 doesn't boot if
CONFIG_ESP32_WIFI_NET_ALLOC_SPIRAMis combined withCONFIG_SPI - #107633 - USB-Next: CDC-ACM: Incomplete transmission on MCUmgr
- #108120 - STM32WBAx : Flash process request is not handled
- #108637 - tests/drivers/bbram/generic/ fails at random due to drivers/bbram/bbram_microchip_mcp7940n_emul.c
- #108793 - kernel: init: main thread not tagged K_FP_REGS when CONFIG_FPU && CONFIG_FPU_SHARING
- #109128 - fs: backend file resource leak when fs_open with FS_O_TRUNC fails during truncate
- #109383 - stm32wbax: bluetooth: issue when extended Advertising Data Packet length exceeds 250 bytes
- #109403 - net: icmpv6: missing source address guard in net_icmpv6_send_error (RFC 4443 2.4(e.6))
- #109460 - entropy: psa:
ENTROPY_PSA_CRYPTO_RNGdeprecated without migration path - #109602 - espressif: esp32c5/esp32s3: fix PSRAM + Wi-Fi heap mapping and linker segment sizing bugs
- #109641 -
west spdxfails on Windows if project is on a different drive - #109907 - tests: dma: chan_blen_transfer: test case is not synchronized with transfer callback
- #110018 - drivers: gpio: esp32: GPIO deep sleep wakeup requires CONFIG_PM
- #110077 - k_pipe_read in ISR causing fault
- #110303 - Bluetooth: Mesh: PrivateBeaconKey PSA key leak after subnet deletion
- #110643 - drivers: stepper: adi_tmc: tmc51xx configure_ramp appears to use child device for clock lookup
- #110645 - net: sockets: recvmsg() ancillary-data capacity check undercounts cmsg size
- #110651 - usb: device_next: cdc_ncm: TX thread deadlocks when usbd_ep_enqueue() fails
- #110654 - drivers: can: nxp: flexcan: bus errors when transmitting leads to log flooding
- #110749 - drivers: uart: sercom g1: async RX of a 1-byte buffer writes one byte past the buffer
- #110757 - xtensa: ptables: deinitialized memory domain is left on the global domain list
- #110762 - bluetooth: classic: hfp_hf: cind_handle_values() writes past ind_table on a long +CIND list
- #110766 - drivers: serial: pl011: TX enable spins forever when CTS flow control blocks transmission
- #110771 - net: sockets: getaddrinfo() retry after a DNS timeout leaves the previous query in flight and touches stale stack state
- #110775 - Bluetooth: BAP: unicast client dereferences NULL stream->qos when a QoS Configured notification arrives before the stream is added to a group
- #110849 - bluetooth: classic: sdp: bt_sdp_parse_attribute() reads one byte past the buffer end
- #110854 - bluetooth: classic: rfcomm: session stuck and L2CAP channel leaked when both sides disconnect simultaneously
- #110857 - net: sntp: close-while-polling use-after-free in
sntp_close_async - #110866 - net: dns:
.localsuffix check reads past the end of the hostname string - #110915 - pb-adv bearer resets the protocol timer unconditionally
- #110954 - drivers: disk: ftl: dhara callbacks write through NULL error pointer on flash error
- #110956 - Bluetooth: ISO: bt_iso_recv() pulls the SDU header without checking buf->len
- #110967 - Bluetooth: BAP: Broadcast Assistant shares one att_buf across all connections
- #111016 - kernel: userspace: dynamic kernel-object list freed under a different lock than it is traversed
- #111020 - usb: host: ctx->root left dangling after root device disconnect
- #111031 - tests/drivers/can/api/drivers.can.api fails on mutex
- #111032 - tests/net/lib/tls_credentials/net.tls_credentials.trusted_tfm fails on mutex
- #111056 - Wireguard replay issue
- #111082 - net: wireguard: incoming data packet can overflow the linearization buffer
- #111087 - kernel: k_thread_name_copy() syscall dereferences NULL for an unregistered thread pointer
- #111100 - kernel: pipe: a user thread can re-initialize a pipe that is already in use
- #111110 - kernel: poll: z_vrfy_k_poll() leaks events_copy when a k_poll_event carries an invalid object handle
- #111116 - pmci: mctp: I2C+GPIO target writes received bytes through an unchecked/unallocated packet buffer
- #111119 - drivers: spi: dw: spi_dw_configure() uses config->frequency as a divisor without validating it
- #111238 - net: http: server: spurious zsock_poll() return of 0 leaks sockets and corrupts the kernel timeout list
- #111277 - Neighbor solicitation header hop limit issue when CONFIG_NET_IPV6_ROUTE_MCAST is enabled
- #111345 - net: http_server: static filesystem handler serves files outside the web root for paths containing ".."
- #111407 - kernel: userspace: thread_idx_alloc() races on SMP and can hand out duplicate thread indices
- #111411 - ESP32-S3 + Octal PSRAM: runtime flash erase/write fails with ESP_ERR_NOT_FOUND (261) — esp_flash driver chip initialized before PSRAM re-tunes MSPI
- #111412 - drivers: i2c: i2c_dw: target stays stuck in CMD_SEND, write_requested() stops firing
- #111416 - logging: z_vrfy_log_filter_set() accepts a negative src_id and indexes outside log_dynamic
- #111420 - debug: coredump/shell: out-of-bounds read printing a stored coredump's target
- #111427 - bluetooth: host: gatt_write_ccc_rsp() uses subscription params after releasing them
- #111431 - net: ip: forwarded packets keep their original TTL / hop-limit (no decrement on the routing path)
- #111447 - tests: arch: arm: Exclude custom IRQ controllers from IRQ test
- #111481 - drivers: display: display_ili9xxx.c: x/y resolution changes breaks sample
- #111534 - Bluetooth: GATT: notify/indicate checks the declaration's permissions, not the value's, when passed a characteristic declaration
- #111545 - hal_espressif Kconfig can cause build to crashes if ZEPHYR_HAL_ESPRESSIF_MODULE_DIR is undefined
- #111564 - bluetooth: host: classic: l2cap_br: Fix conf req/rsp length validation
- #111888 - drivers: pwm: mcux_sctimer: counter stranded when device resumes before first channel config
- #111929 - net: bridge: Memory leak on broadcast, multicast or matching MAC in eth_bridge_input_process.
- #111935 - flash: z_vrfy_flash_copy is missing proper set of K_SYSCALL_DRIVER_FLASH invocations
- #111936 - fs: ext2: Avoid using 0 value inode and block per group in calculations
- #112027 - Bluetooth: esp32c3: bonding with pairing keys on Zephyr 4.4.1 hangs
- #112204 - net: sockets: recvmsg() ancillary write checks total buffer, not room at the chosen slot
- #112211 - Bluetooth: BAP: UC: NULL stream->group dereference on QoS Configured notification
- #112235 - az3166_iotdevkit: Button B never gets released
- #112315 - fs: ext2: Lack of validation of s_block_count, read from superblock, permitted block bitmap to be larger than ext2 block size
- #112325 - Out-of-bounds read in PTP receive path: unchecked 4-bit message type indexes
- #112421 - net: dhcp: name-lookup bounds checks use sizeof() instead of ARRAY_SIZE()
- #112424 - net: ocpp: RPC-frame field parsing reads past fixed buffers on long/unterminated input
- #112427 - mgmt: hawkbit: 1-byte heap overrun when NUL-terminating the response buffer
- #112430 - Bluetooth: Host: bt_att_sent dereferences a freed channel after disconnect mid-transfer
- #112432 - drivers: flash: sf32lb_mpi_qspi_nor: read/write offset check wraps on a negative offset
- #112435 - kernel: k_queue_peek_head()/k_queue_peek_tail() dereference a node without holding the queue lock
- #112441 - mgmt: updatehub: socket leak, NULL deref, and concurrency bugs in the OTA client
- #112555 - drivers: bluetooth: hci_bflb / hci_bee: send() consumes the buffer on error paths
- #112559 - usb: device_next: dfu: handle_download() dereferences buf without a NULL check
- #112609 - drivers: usb: udc: MAX32 USB driver problem about nodata setup messages
- #112613 - usb: device_next: CDC NCM to-host control handler ignores wLength when building responses
- #112616 - net: sockets: userspace sendmsg/recvmsg verifiers re-read live user msghdr after copying it
- #112621 - llext: ELF loader indexes arrays and sizes a stack VLA from unvalidated module header fields
- #112782 - mgmt/settings: heap buffers leaked on access-hook and OOM paths in settings read/write/delete
- #112838 - Bluetooth: Host: GATT: parse_read_std_char_desc() loops forever when a Read By Type Response has len 0
- #112852 - logging: z_vrfy_z_log_msg_static_create() does not validate its arguments
- #112931 - serial: pl011: error interrupts are never acknowledged and stay latched
- #113039 - drivers: modem: hl7800 and wncm14a2a AT-response handlers write past fixed stack buffers
- #113043 - net: 6lo: get_ihpc_inlined_size() reads past da_inline_size_table for reserved destination modes
- #113048 - net: ipv6: handle_ra_6co() underflows memset length for context_len > 128
- #113159 - LVGL Dynamic allocation doesn't work
- #113265 - Bluetooth: Host: AoD 2US CTE type not validated in valid_conn_cte_tx_params()
- #113266 - kernel: thread: thread_obj_validate() fails to oops a denied k_thread_join/k_thread_abort
- #113299 - net: route: net_route_packet_if() forwards packets without decrementing the hop limit
- #113303 - wifi: airoc: TX net_buf is leaked when whd_network_send_ethernet_data() fails
- #113307 - mbox: userspace: z_vrfy_mbox_send validates msg->data then forwards the mutable userspace pointer
- #113324 - fs: ext2: mount does not validate superblock s_log_block_size
- #113328 - net: ocpp: server-message parsers mishandle malformed and oversized fields
- #113339 - midi2: UMP Stream notification replies transmit uninitialised stack bytes
- #113343 - drivers: virtio: device-supplied ring id and PCI cap_len used without bounds checking
- #113346 - bluetooth: audio: has: notification work runs with NULL attributes when a bonded peer reconnects before bt_h...
Zephyr v4.3.1
This is a maintenance release with fixes.
Issues Fixed
These GitHub issues were addressed since the previous 4.3.0 tagged release:
- #55186 - posix:
fnmatch: fix known bugs - #61464 - USB device stack (new and old) assertion on STM32
- #95359 -
spi_loopbackfails onfrdm_rw612with DMA and/orcs_loopback - #96699 - drivers: spi: nrf_spim: Unused function warning when
CONFIG_DEVICE_DEINIT_SUPPORTis disabled - #96762 - drivers: serial: uart_nrfx_uarte: Unused function warning when
CONFIG_DEVICE_DEINIT_SUPPORTis disabled - #98491 - riscv: userspace: undefined symbol:
z_stack_space_get - #98501 - pm: device_runtime: Issues with set/clear
PD_CLAIMEDflag inISR_SAFEcontext - #98523 - ring_buffer:
ring_buf_initmay trigger assertion depending on Kconfig - #98588 - drivers: i2c: dw_i2c: i2c read time out on certain type of
DW_I2C - #98768 - STM32F303 bxCAN: Last 2 bytes corrupted on TX pin, but registers are correct
- #98782 - esp32c6: esp32h2: OpenThread issue
- #98797 - boards: nxp:
mimxrt1180_evk: J-Link script file not used when debugging - #99099 - STM32 QSPI sample shifting prevents communication with
GD25Q128Eflash chip - #99453 - sensor: current-amp:
zero-current-offsetno longer works - #99490 - MAX32650 SoC system clock configuration problem
- #99491 - hwinfo: hwinfo test fails for MAX32657EVKIT board
- #99535 - Issue with STM32 Ethernet and KSZ8081 Phy
- #99563 - RP2350 Hazard3 doesn't default to XIP
- #99588 - Bluetooth: Controller: nRF54Lx Radio Tx Power incorrect
- #99644 - Siwx91x Compilation error with PM
- #99659 - OpenThread Border Router issues in 4.3.0 release
- #99682 - net: lib: dns: Unpacking query name can overflow the destination buffer
- #99762 - mcumgr: Image management incorrectly identifies active slot when slots are on different flash devices
- #99792 - HTTP Server Shows Error Log Message when iface goes down
- #99795 - Telnet Shell Server Shows Error Log Message when iface goes down
- #99797 - MCUmgr: OS: DateTime: Millisecond parsing erroneous
- #99822 - stm32 EXTI driver: add support for STM32N6
- #99895 -
npcx9m6f_evbandfrdm_k64f:kernel.common.stack_protection_arm_fpu_sharingfails - #99901 - drivers: entropy: gecko_trng: Error when getting entropy too soon after init
- #99904 - soc: silabs: siwx91x: irq prio misalignment with hal
- #99948 - drivers: ice40_fpga:
k_usleepwhile holding a spinlock - #100040 - timer: cortex_m_systick: Compilation error if
CONFIG_TIMER_READS_ITS_FREQUENCY_AT_RUNTIMEis defined - #100211 - soc: silabs: siwx91x: ADC driver returns constant 0 mV
- #100212 - No event code filterint for LVGL pointer process
- #100225 - bluetooth:
bt_connreference leak in Frame Space Update in Zephyr 4.3.0 - #100296 -
west packages pip --installfails with permission error - #100715 - mgmt: mcumgr: firmware loader allows for self erasure
- #100754 - bt test commands not working/crashing for nRF54LM20A DK board
- #100903 - drivers: flash: stm32 ospi: detected erase type is always resetted
- #101048 - drivers: xen: Uninitialized variable warning
- #101151 - drivers: serial: NXP uart_mcux_flexcomm: instance interrupt config not saved during
PM_DEVICE_ACTION_TURN_OFF - #101236 - NXP: Failed to disable
random-mac-addressin ethernet driver. - #101401 - logging: thread starvation for lower-priority producers
- #101414 -
ZVFS_OPEN_SIZEdefine applied irrespective of configuration - #101416 - It seems TCP accept had some issue during link changes
- #102129 - Flash incorrectly tested on MAX32657 NS due to
storage_partition - #102635 - gpio: mcux: Potential infinite interrupt hang when configuring
- #102995 - OpenThread: build fails with
CONFIG_OPENTHREAD_MTDenabled - #103029 - NVS startup fails after power loss during final ATE write
- #103140 - TCAN4x5x initialization stalls with latest driver changes
- #103239 - Race condition on usart/eusart silabs driver
- #103242 - Watchdog timer on Siwx91x devices is not on pause during deep sleep
- #103329 - Shared Flash access might be corrupted on SiWx91x SoC
- #103339 - PM on SiWG91x SoC is broken
- #103365 - MAX32655 UART fails to send some bytes on Zephyr 4.3
- #103962 - RTIO: SQE flags not zeroed by some functions
- #104208 - IPv4/6 fragmentation memory leak
- #104248 - DNS query packet length check
- #104253 - driver: clock_control:
RCC_BDCR_LSEDRV_Posundefined using STM32L0 - #104652 - net: socketcan: length not always verified
- #104748 - mcumgr: error codes of group "stat" incorrect
- #104948 - net: lib: socket: tls: Potential out-of-bounds write in
socket_op_vtable.connect - #105038 - net: lib: sockets: tls: Improve socket address storage
- #105106 - arc: mpu: MPUv6 buffer validation race condition causes spurious access denials
- #105216 - drivers: timer: stm32_lptim: fix incorrect configuration and harden against wrong usage
- #105374 - drivers: gpio: sam: callback called when interrupt disabled
- #105644 - SNTP uncertainty option invalids
sntp_query - #105754 - net: sockets:
msg->msg_iovlenis not validated inzsock_recvmsgsys call - #106109 - wifi: wifi_credentials: Static credentials are not validated
- #106291 - Build fails when
CONFIG_OPENTHREAD_CONFIG_DIAG_ENABLEis enabled. - #106334 - Thread-safety race condition in
net_buf_unref - #106776 - net: tcp: Non-blocking connect failure leaks SYN retransmissions
- #106894 - update Mbed TLS to 3.6.6
- #106991 - net: tcp: use-after-free in
net_tcp_foreachcauses bus fault - #107081 - McuMgr
fs_mgmt_file_uploadhandler does not check partial writes to filesystem - #107096 -
cc3220sf_launchxl/cc3220sfmissing ZVFS selection in sample - #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
- #107920 - net: icmp: assert triggered sending icmp echo response with
CONFIG_NET_STATISTICS - #107928 - net: lib: http_server: fix in websocket
- https...
Zephyr v4.3.1-rc1
Issues fixed
These GitHub issues were addressed since the previous 4.3.0 tagged release:
- #55186 - posix: fnmatch: fix known bugs
- #61464 - USB device stack (new and old) assertion on STM32
- #95359 - spi_loopback fails on frdm_rw612 with DMA and/or cs_loopback
- #96699 - drivers: spi: nrf_spim: Unused function warning when driver deinit Kconfig is disabled
- #96762 - drivers: serial: uart_nrfx_uarte: Unused function warning when driver deinit Kconfig is disabled
- #98491 - riscv: userspace: undefined symbol: z_stack_space_get
- #98501 - pm: device_runtime: Issues with set/clear PD_CLAIMED flag in ISR_SAFE context
- #98523 - ring_buffer: ring_buf_init may trigger assertion depending on Kconfig
- #98588 - drivers: i2c: dw_i2c: i2c read time out on certain type of DW_I2C
- #98768 - STM32F303 bxCAN: Last 2 bytes corrupted on TX pin, but registers are correct
- #98782 - esp32c6: esp32h2: Openthread issue
- #98797 - boards: nxp: mimxrt1180_evk: Jlink script file not used when debugging
- #99099 - STM32 QSPI sample shifting prevents communication with GD25Q128E flash chip
- #99453 - sensor: current-amp: zero-current-offset no longer works
- #99490 - MAX32650 SoC system clock configuration problem
- #99491 - hwinfo: hwinfo test fails for MAX32657EVKIT board
- #99535 - 4.3.0 : Issue with STM32 Ethernet and KSZ8081 Phy
- #99563 - RP2350 Hazard3 doesnt default to XIP
- #99588 - Bluetooth: Controller: nRF54Lx Radio Tx Power incorrect
- #99644 - Siwx91x Compilation error with PM
- #99659 - OpenThread Border Router issues in 4.3 release
- #99682 - net: lib: dns: Unpacking query name can overflow the destination buffer
- #99762 - mcumgr: Image management incorrectly identifies active slot when slots are on different flash devices
- #99792 - HTTP Server Shows Error Log Message when iface goes down
- #99795 - Telnet Shell Server Shows Error Log Message when iface goes down
- #99797 - MCUmgr: OS: DateTime: Millisecond parsing erroneous
- #99822 - stm32 EXTI driver: add support for STM32N6
- #99895 - npcx9m6f_evb and frdm_k64f: kernel.common.stack_protection_arm_fpu_sharing fails
- #99901 - drivers: entropy: gecko_trng: Error when getting entropy too soon after init
- #99904 - soc: silabs: siwx91x: irq prio misalignment with hal
- #99948 - drivers: ice40_fpga: k_usleep while holding a spinlock
- #100040 - timer: cortex_m_systick: Compilation error if CONFIG_TIMER_READS_ITS_FREQUENCY_AT_RUNTIME is defined
- #100211 - soc: silabs: siwx91x: ADC driver returns constant 0 mV
- #100212 - No event code filterint for LVGL pointer process
- #100225 - bluetooth: bt_conn reference leak in Frame Space Update in Zephyr 4.3.0
- #100296 - west packages pip --install fails with permission error
- #100715 - mgmt: mcumgr: firmware loader allows for self erasure
- #100754 - bt test commands not working/crashing for nRF54LM20A DK board
- #100903 - drivers: flash: stm32 ospi: detected erase type is always resetted
- #101048 - drivers: xen: Uninitialized variable warning
- #101151 - drivers: serial: NXP uart_mcux_flexcomm: instance interrupt config not saved during PM_DEVICE_ACTION_TURN_OFF
- #101236 - NXP: Failed to disable random-mac-address in ethernet driver.
- #101401 - logging: thread starvation for lower-priority producers
- #101414 - ZVFS_OPEN_SIZE define applied irrespective of configuration
- #101416 - It seems tcp accept had some issue during link changes
- #102129 - Flash incorrectly tested on MAX32657 NS due to storage_partition
- #102635 - gpio: mcux: Potential infinite interrupt hang when configuring
- #102995 - OpenThread: build fails with CONFIG_OPENTHREAD_MTD enabled
- #103029 - NVS startup fails after power loss during final ATE write
- #103140 - TCAN4x5x initialization stalls with latest driver changes
- #103239 - Race condition on usart/eusart silabs driver
- #103242 - Watchdog timer on Siwx91x devices is not on pause during deep sleep
- #103329 - Shared Flash access might be corrupted on SiWx91x SoC
- #103339 - PM on SiWG91x SoC is broken
- #103365 - MAX32655 UART fails to send some bytes on Zephyr 4.3
- #103962 - RTIO: SQE flags not zeroed by some functions
- #104208 - IPv4/6 fragmentation memory leak
- #104248 - DNS query packet length check
- #104253 - driver: clock_control: RCC_BDCR_LSEDRV_Pos undefined using STM32L0
- #104652 - net: socketcan: length not always verified
- #104748 - [mcumgr] error codes of group "stat" incorrect
- #104948 - net: lib: socket: tls: Potential out-of-bounds write in socket_op_vtable::connect
- #105038 - net: lib: sockets: tls: Improve socket address storage
- #105106 - arc: mpu: MPUv6 buffer validation race condition causes spurious access denials
- #105216 - drivers: timer: stm32_lptim: fix incorrect configuration and harden against wrong usage
- #105374 - drivers: gpio: sam: callback called when interrupt disabled
- #105644 - SNTP uncertainty option invalids sntp_query()
- #105754 - net: sockets: msg->msg_iovlen is not validated in zsock_recvmsg() sys call
- #106109 - wifi: wifi_credentials: Static credentials are not validated
- #106291 - Build fails when OPENTHREAD_CONFIG_DIAG_ENABLE is enabled.
- #106334 - Thread-safety race condition in net_buf_unref
- #106776 - net: tcp: Non-blocking connect failure leaks SYN retransmissions
- #106894 - update Mbed TLS to 3.6.6
- #106991 - net: tcp: use-after-free in net_tcp_foreach() causes bus fault
- #107081 - McuMgr fs_mgmt_file_upload handler does not check partial writes to filesystem
- #107096 - cc3220sf_launchxl/cc3220sf missing ZVFS selection in sample
- #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
- #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS=y
- #107928 - net: lib: http_server: Fix in websocket must be back ported to 3.7 and 4.3
- #108004 - drivers: entropy: stm32: bad locking sequence
- #108149 - Renaming configuration file in WiFi Shell sample causes errors when building the associated board documentation in branch v4.3-branch
- #108559 - IP address parsing issue
- #108637 - tests/drivers/bbram/generic/ fails at random due to drivers/bbram/bbram_microchip_mcp7940n_emul.c
- #108835 - adin2111: Communication gets stuck after high bandwidth transfer
- #108846 - Validate DNS rdata length in dns_unpack_answer
- #108848 - wifi: nrf70: Missing bounds check on TWT event buffer
- #108963 - net: lwm2m: URI string may be unterminated in FW pull mode
- #109053 - native_sim: FUSE files are opened write-only
- #109063 - The issue in Bluetooth Mesh solicitation PDU parsing
- #109128 - fs: backend file resource leak when fs_open with FS_O_TRUNC fails during truncate
- #109133 - Undefined bitwise shift behavior in PTP port management interval handling
- #109257 - xtensa: mpu: fix arch_buffer_validate() if overflow
- #109549 - Security advisory GHSA-4vqm-pw24-g9jp / CVE 2026-5590 fix not available for Zephyr 4.3
- #109620 - Bluetooth: Controller: Fix OOB read in ISOAL
- #109857 - posix: mqueue: fix integer overflow in mq_open() buffer allocation
- #110032 - fs: ext2: validate directory entry structure before traversal #108226
- #110077 - k_pipe_read in ISR causing fault
- #110303 - Bluetooth: Mesh: PrivateBeaconKey PSA key leak after subnet deletion
- #110393 - bluetooth: l2cap: validate alloc_buf user data
- #110645 - net: sockets: recvmsg() ancillary-data capacity check undercounts cmsg size
- #110651 - usb: device_next: cdc_ncm: TX thread deadlocks when usbd_ep_enqueue() fails
- #110762 - bluetooth: classic: hfp_hf: cind_handle_values() writes past ind_table on a long +CIND list
- #110766 - drivers: serial: pl011: TX enable spins forever when CTS flow control blocks transmission
- #110771 - net: sockets: getaddrinfo() retry after a DNS timeout leaves the previous query in flight and touches stale stack state
- #110775 - Bluetooth: BAP: unicast client dereferences NULL stream->qos when a QoS Configured notification arrives before the stream is added to a group
- #110857 - net: sntp: close-while-polling use-after-free in sntp_close_async
- #110866 - net: dns: .local suffix check reads past the end of the hostname string
- #110915 - pb-adv bearer resets the protocol timer unconditionally
- #110956 - Bluetooth: ISO: bt_iso_recv() pulls the SDU header without checking buf->len
- #110967 - Bluetooth: BAP: Broadcast Assistant shares one att_buf across all connections
- #111016 - kernel: userspace: dynamic kernel-object list freed under a different lock than it is traversed
Zephyr v4.4.1
This is a bugfix release for Zephyr 4.4.0.
Security Vulnerability Related
- CVE-2026-7656 Under embargo until 2026-06-25
- CVE-2026-8718 Under embargo until 2026-08-08
- CVE-2026-9263 Under embargo until 2026-08-28
- CVE-2026-10666 Under embargo until 2026-07-12
- CVE-2026-10673 Under embargo until 2026-07-15
More detailed information can be found in:
https://docs.zephyrproject.org/latest/security/vulnerabilities.html
Issues fixed
The following issues are addressed by this release:
- #99054 - ARM64: Wrong register is being saved in coredump, causing corrupted backtrace show in gdb
- #100542 - soc/espressif/esp32s3: undefined reference to 'log_const_soc' when CONFIG_PM=y
- #104000 - display_check: ASSERTION FAIL / kernel panic in test_display_by_capture on mimxrt700_evk (mimxrt798s/cm33_cpu0, co5300@0)
- #104480 -
samples/subsys/usb/consolehangs when opened with picocom on blackpill_f411ce (STM32F411, Zephyr 4.3.99) - #104900 - Bluetooth LE host qualification for 4.4 release
- #105265 - menuconfig fails on Windows when using multiple shields
- #105317 - mcumgr: os grp: mpstat incorrect cbor layout
- #105521 - Drivers: display: ili9xxx driver color order problem
- #106150 - net: all NXP platform dhcp_client does not work
- #106580 - spi mchp g1 driver configuration issues
- #106850 - sensor ism6hg256x returns wrong values via the shell
- #106872 - ethernet: dwmac: no multicast packets are received
- #106906 - Fix CSI data overflow issue
- #106971 - hardfault on boot with samples/hello_world for old flash dts layout NXP platforms
- #106984 - Regression in net/ethernet.h: C++ build failure (invalid cast from const void *)
- #106991 - net: tcp: use-after-free in net_tcp_foreach() causes bus fault
- #107061 - settings: runtime:
settings_runtime_setcrashes whenh_setis NULL - #107067 - Sensor:Driver:ST: lsm6dsvxxxx - IRQ pin goes high before GPIO IRQ is set
- #107081 - McuMgr fs_mgmt_file_upload handler does not check partial writes to filesystem
- #107105 - Sensor:Driver:ST: lsm6dsvxxxx - setting the SFLP changes the ODR for mag and accel
- #107201 - drivers: ethernet: esp32: DMA buffer processing skips some buffers if multiple ready
- #107302 - Secure Storage not enabling
PSA_CRYPTO - #107355 - stm32: H7RS: backup access for reading some RTC registers
- #107388 - mcxw7x ieee driver / OT samples: DUT can not attach to network when SED/SSED
- #107398 - OpenThread Border Router cannot forward inbound multicast packets on ethernet
- #107412 - mcause: 2, Illegal instruction on ESP32-C3 when using localtime_r with tzset()
- #107422 - ESP32S3 PSRAM is not working properly: only work in octal+40M
- #107442 - samples/drivers/adc/adc_dt prints garbage data on ADCs with <= 16-bit buffer
- #107540 - esp32c5_devkitc psram size
- #107585 - soc: st: stm32h7x: NUM_IRQS computed too small since Zephyr 4.4, causing build failure
- #107589 - net: dns: Forward all DNS packets if callback is installed still not functional
- #107594 - mgmt: mcumgr: grp: img_mgmt: Non-progressive erase in swap using offset mode erases out of bounds
- #107621 - Flashing MAX32 devices with OpenOCD picks first connected device and ignores
--serialoption - #107627 - STM32 F4 with external USB PHY fails to build
- #107632 - MAX32 SPI driver race condition leads to timed out transceive transactions
- #107675 - stm32: nucleo-wba65ri 'ns' variant fails to boot
- #107773 - Stepper: adi_tmc: Build fails with unresolved function read_actual_position()
- #107809 - BusFault in mcumgr_serial_process_frag() when net_buf allocation fails
- #107814 - samples: net: HTTP server configuration is broken
- #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
- #107908 - Fix missing ESP32-C5 uart test coverage
- #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS=y
- #107938 - drivers: sdhc: sam_hsmci: Initialize variables
- #108004 - drivers: entropy: stm32: bad locking sequence
- #108035 - STM32WBAx : Thread GRL tests failure due to 15.4 driver issue
- #108258 - mapped-partition linker fails with non-XIP boot
- #108267 - STM32 TF-M regression.sh script corrupted after 'west flash'
- #108285 - PM issues regarding STM32WB09 in Zephyr v4.4.0
- #108391 - flash_shell does not consider erase command size argument
- #108466 - net: sockets: tls:
addrmay be used uninitialized - #108559 - IP address parsing issue
- #108631 - tests/lib/devicetree/api_ext fails to build for some targets
- #108633 - IRK is not sent to controller when extended advertisement enabled but started via bt_le_adv_start
- #108636 - tests/subsys/zbus/proxy_agent/ipc_backend fails for nrf5340bsim//cpunet
- #108680 - drivers.flash.common.test_storage_partition fails for nrf54l15bsim/nrf54l15/cpuapp
- #108681 - Broken link in release note of Zephyr 4.4
- #108737 - Update MCUboot to v2.4.0 release
- #108785 - Bluetooth: ESP32-S3 + iOS: HCI 0x3D MIC failure on every reconnect after LE SC pair
- #108835 - adin2111: Communication gets stuck after high bandwidth transfer
- #108846 - Validate DNS rdata length in dns_unpack_answer
- #108848 - wifi: nrf70: Missing bounds check on TWT event buffer
- #108915 - modem: cmux: user pipe flow control stuck
- #108963 - net: lwm2m: URI string may be unterminated in FW pull mode
- #109053 - native_sim: FUSE files are opened write-only
- #109188 - drivers: ethernet: esp32: unused driver static function when ref_clk_output_gpios is not used
- #109257 - xtensa: mpu: fix arch_buffer_validate() if overflow
- #109325 - soc: esp32: abort() while using sleep-hold-en flag
- #109497 - OpenThread Border Router - Incorrect computation of IPV6 packet checksum
- #109515 - MAX32 USB support broken for some transfer types on Zephyr 4.4
- #109577 - esp32: gpio: gpio overflow due to BIT operation
- #109620 - Bluetooth: Controller: Fix OOB read in ISOAL
- #109625 - net: sockets/tls: validate buffer in peer_connection_id_value_get
- #109652 - drivers: mcux_flexcomm: missing init_common() on PM_DEVICE_ACTION_RESUME and SUSPEND for I2C, UART, I2S, SPI
- #109759 - drivers: can: mcux: flexcan: Fix off-by-one error in MB IRQ handling
- #109848 - Usage fault due to unaligned access in BLE Mesh on MCXW23
- #109857 - posix: mqueue: fix integer overflow in mq_open() buffer allocation
- #109860 - ESP32 PSRAM may abort() when cache invalidate is called
- #109869 - Espressif's esptool may fail depending on elf segment alignment
- #109899 - STM32 ADC differential channel issue
- #110019 - pm: esp32: GPIO_INT_WAKEUP flag usage with CONFIG_INPUT
- #110032 - fs: ext2: validate directory entry structure before traversal #108226
- #110079 - Backport 108049 [arm64: Fix clang unused warnings in mmu.c] to v4.4-branch
Zephyr v4.4.1-rc1
Issues fixed
These GitHub issues were addressed since the previous 4.4.0 tagged release:
- #99054 - ARM64: Wrong register is being saved in coredump, causing corrupted backtrace show in gdb
- #100542 - soc/espressif/esp32s3: undefined reference to 'log_const_soc' when CONFIG_PM=y
- #104000 - display_check: ASSERTION FAIL / kernel panic in test_display_by_capture on mimxrt700_evk (mimxrt798s/cm33_cpu0, co5300@0)
- #104480 -
samples/subsys/usb/consolehangs when opened with picocom on blackpill_f411ce (STM32F411, Zephyr 4.3.99) - #104900 - Bluetooth LE host qualification for 4.4 release
- #105265 - menuconfig fails on Windows when using multiple shields
- #105317 - mcumgr: os grp: mpstat incorrect cbor layout
- #105521 - Drivers: display: ili9xxx driver color order problem
- #106150 - net: all NXP platform dhcp_client does not work
- #106580 - spi mchp g1 driver configuration issues
- #106850 - sensor ism6hg256x returns wrong values via the shell
- #106872 - ethernet: dwmac: no multicast packets are received
- #106906 - Fix CSI data overflow issue
- #106971 - hardfault on boot with samples/hello_world for old flash dts layout NXP platforms
- #106984 - Regression in net/ethernet.h: C++ build failure (invalid cast from const void *)
- #106991 - net: tcp: use-after-free in net_tcp_foreach() causes bus fault
- #107061 - settings: runtime:
settings_runtime_setcrashes whenh_setis NULL - #107067 - Sensor:Driver:ST: lsm6dsvxxxx - IRQ pin goes high before GPIO IRQ is set
- #107081 - McuMgr fs_mgmt_file_upload handler does not check partial writes to filesystem
- #107105 - Sensor:Driver:ST: lsm6dsvxxxx - setting the SFLP changes the ODR for mag and accel
- #107201 - drivers: ethernet: esp32: DMA buffer processing skips some buffers if multiple ready
- #107302 - Secure Storage not enabling
PSA_CRYPTO - #107355 - stm32: H7RS: backup access for reading some RTC registers
- #107388 - mcxw7x ieee driver / OT samples: DUT can not attach to network when SED/SSED
- #107398 - OpenThread Border Router cannot forward inbound multicast packets on ethernet
- #107412 - mcause: 2, Illegal instruction on ESP32-C3 when using localtime_r with tzset()
- #107422 - ESP32S3 PSRAM is not working properly: only work in octal+40M
- #107442 - samples/drivers/adc/adc_dt prints garbage data on ADCs with <= 16-bit buffer
- #107540 - esp32c5_devkitc psram size
- #107585 - soc: st: stm32h7x: NUM_IRQS computed too small since Zephyr 4.4, causing build failure
- #107589 - net: dns: Forward all DNS packets if callback is installed still not functional
- #107594 - mgmt: mcumgr: grp: img_mgmt: Non-progressive erase in swap using offset mode erases out of bounds
- #107621 - Flashing MAX32 devices with OpenOCD picks first connected device and ignores
--serialoption - #107627 - STM32 F4 with external USB PHY fails to build
- #107632 - MAX32 SPI driver race condition leads to timed out transceive transactions
- #107675 - stm32: nucleo-wba65ri 'ns' variant fails to boot
- #107773 - Stepper: adi_tmc: Build fails with unresolved function read_actual_position()
- #107809 - BusFault in mcumgr_serial_process_frag() when net_buf allocation fails
- #107814 - samples: net: HTTP server configuration is broken
- #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
- #107908 - Fix missing ESP32-C5 uart test coverage
- #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS=y
- #107938 - [backport]: drivers: sdhc: sam_hsmci: Initialize variables
- #108004 - drivers: entropy: stm32: bad locking sequence
- #108035 - STM32WBAx : Thread GRL tests failure due to 15.4 driver issue
- #108258 - mapped-partition linker fails with non-XIP boot
- #108267 - STM32 TF-M regression.sh script corrupted after 'west flash'
- #108285 - PM issues regarding STM32WB09 in Zephyr v4.4.0
- #108391 - flash_shell does not consider erase command size argument
- #108466 - [v4.4] net: sockets: tls:
addrmay be used uninitialized - #108559 - IP address parsing issue
- #108631 - tests/lib/devicetree/api_ext fails to build for some targets
- #108633 - IRK is not sent to controller when extended advertisement enabled but started via bt_le_adv_start
- #108636 - tests/subsys/zbus/proxy_agent/ipc_backend fails for nrf5340bsim//cpunet
- #108680 - drivers.flash.common.test_storage_partition fails for nrf54l15bsim/nrf54l15/cpuapp
- #108681 - Broken link in release note of Zephyr 4.4
- #108737 - [v4.4-branch] Update MCUboot to v2.4.0 release
- #108785 - Bluetooth: ESP32-S3 + iOS: HCI 0x3D MIC failure on every reconnect after LE SC pair
- #108835 - adin2111: Communication gets stuck after high bandwidth transfer
- #108846 - Validate DNS rdata length in dns_unpack_answer
- #108848 - wifi: nrf70: Missing bounds check on TWT event buffer
- #108915 - modem: cmux: user pipe flow control stuck
- #108963 - net: lwm2m: URI string may be unterminated in FW pull mode
- #109053 - native_sim: FUSE files are opened write-only
- #109188 - drivers: ethernet: esp32: unused driver static function when ref_clk_output_gpios is not used
- #109257 - [backport] xtensa: mpu: fix arch_buffer_validate() if overflow
- #109325 - soc: esp32: abort() while using sleep-hold-en flag
- #109497 - OpenThread Border Router - Incorrect computation of IPV6 packet checksum
- #109515 - MAX32 USB support broken for some transfer types on Zephyr 4.4
- #109516 - [Backport v4.4-branch] Failed to backport #108447
- #109577 - esp32: gpio: gpio overflow due to BIT operation
- #109620 - [backport] Bluetooth: Controller: Fix OOB read in ISOAL
- #109625 - [backport] net: sockets/tls: validate buffer in peer_connection_id_value_get
- #109652 - drivers: mcux_flexcomm: missing init_common() on PM_DEVICE_ACTION_RESUME and SUSPEND for I2C, UART, I2S, SPI
- #109759 - drivers: can: mcux: flexcan: Fix off-by-one error in MB IRQ handling
- #109848 - Usage fault due to unaligned access in BLE Mesh on MCXW23
- #109857 - [backport] posix: mqueue: fix integer overflow in mq_open() buffer allocation
- #109860 - ESP32 PSRAM may abort() when cache invalidate is called
- #109869 - Espressif's esptool may fail depending on elf segment alignment
- #109899 - v4.4: STM32 ADC differential channel issue
- #110019 - pm: esp32: GPIO_INT_WAKEUP flag usage with CONFIG_INPUT
- #110032 - [backport] fs: ext2: validate directory entry structure before traversal #108226
- #110071 - [Backport v4.4-branch] Failed to backport #109304
- #110079 - Backport 108049 [arm64: Fix clang unused warnings in mmu.c] to v4.4-branch
- #110369 - Zephyr 4.4.1 Release
- #110373 - [Backport v4.4-branch] Failed to backport #109651
Zephyr 4.4.0
We are pleased to announce the release of Zephyr 4.4.0!
For a closer look at some of the key additions in this release, check out the announcement article on the Zephyr blog, along with its companion video.
Major enhancements with this release include:
OpenRISC support
Zephyr now supports the OpenRISC architecture.
Toolchain updates: Zephyr SDK 1.0 and C17
Zephyr 4.4 is the first release to support Zephyr SDK 1.0, with an upgraded GNU toolchain, experimental Clang/LLVM support, and multi-platform QEMU and OpenOCD host tools.
Zephyr now defaults to C17 as its minimum required C standard version.
Networking enhancements
The Wi-Fi management stack now supports Wi-Fi P2P (Wi-Fi Direct), allowing devices to discover and connect directly without a traditional access point.
The networking stack also adds support for WireGuard VPN, enabling secure, low-overhead tunneling.
USB host
Experimental USB host support has been significantly expanded with a new host-class driver framework and support for UVC cameras on Zephyr devices acting as USB hosts.
New driver classes
Zephyr 4.4 adds several new driver APIs, including:
- One-Time Programmable (OTP) memory devices for provisioning and reading permanent device data,
- A biometrics API for integrating biometric sensors such as fingerprint scanners or facial recognition systems, and
- A Wake-up Controller (WUC) API for managing wake-up sources that can bring the system out of low-power states.
Zbus async listeners and proxy agents
Zbus async listeners enable non-blocking observer callbacks via workqueues.
Zbus proxy agents extend publish-subscribe messaging across CPU and domain boundaries over IPC.
Pressure-based CPU frequency scaling
The experimental CPU frequency scaling subsystem now includes a pressure-based policy that adjusts CPU frequency according to scheduler load.
ARM Cortex-M context switching performance improvements
A new context switch implementation for ARM Cortex-M, enabled via CONFIG_USE_SWITCH, delivers significant performance improvements.
NAND flash support
A new Flash Translation Layer (FTL) disk driver (zephyr,ftl-dhara) provides wear leveling and bad block management and enables NAND flash memories to be utilized as standard disk devices.
Developer experience improvements
This release adds several new tools and improvements to development and testing workflows:
- A new dashboard consolidates build information such as RAM and ROM footprint, Devicetree configuration, subsystem initialization levels, and more in a single report.
- A new display driver for QEMU targets simplifies development of display-based applications in environments where the native simulator is unavailable.
- A new heap hardening mechanism (
CONFIG_SYS_HEAP_HARDENING) provides multiple levels of runtime protection against heap corruption. - New scope-based cleanup helpers provide RAII/defer-style automatic cleanup in C when leaving scope.
- The new ztest benchmarking framework provides a standardized way to create cycle-accurate benchmarks, with automated data collection, overhead compensation, and statistical reporting.
Expanded board support
This release adds support for 121 new boards and 31 new shields.
Full Release Notes
The full release notes and list of major changes since the last release can be found here.
An overview of the changes required or recommended when migrating your application from Zephyr
v4.3.0 to Zephyr v4.4.0 can be found in the separate migration guide.
Release Lifecycle
The 4.4 release will be supported until April 12th, 2027.
Additional release information may be found on the Release Management Wiki.
Thanks 🙏
Many thanks to the 931 individuals who contributed to this release! 🚀
Maureen, Stephanos, and the Zephyr Release Team
Zephyr v4.4.0-rc3
Hi Zephyr developers!
The third release candidate for Zephyr 4.4.0 has been tagged:
https://github.com/zephyrproject-rtos/zephyr/releases/tag/v4.4.0-rc3
The merge window for features and enhancements remains closed until 4.4.0 is released.
We continue in the stabilization phase, and only blocker bug-fixes and documentation patches may be merged to the main branch. As a reminder to maintainers, please send PRs to update the release notes and migration guide for any areas you manage.
You may continue to submit pull requests for new features to gather feedback early or collaborate with others, but the release team would like to encourage everyone to focus on testing, fixing any blocker bugs found, and finalizing release notes.
Other bugs which are not critical enough to be categorized as blocker, but should still be part of 4.4 should be marked with the backport v4.4-branch label so they can be considered for the first dot release.
Regards,
The Zephyr Release Team
Release milestone dates:
https://github.com/zephyrproject-rtos/zephyr/wiki/Release-Management
Release process:
https://docs.zephyrproject.org/latest/project/release_process.html
Blocker bugs process:
https://docs.zephyrproject.org/latest/project/release_process.html#blocker-bugs
Regards,
The release team.
Zephyr v4.4.0-rc2
Hello Zephyr developers!
The second release candidate for Zephyr 4.4.0 has been tagged:
https://github.com/zephyrproject-rtos/zephyr/releases/tag/v4.4.0-rc2
We are still in the stabilization phase, and only bug-fix, documentation, and stabilization patches may be merged to the main branch. Matching bug reports for bugfix pull requests are recommended but not required.
You may continue to submit pull requests for new features to gather feedback early or collaborate with others, but the release team would like to encourage everyone to focus on testing, documentation improvements, and fixing bugs. Any feature pull requests should be tagged with the 4.5.0 release milestone.
We anticipate the coming weeks to be very busy reducing overall bug count. Please give this RC a test drive and report any issues on supported platforms (with a PR if possible).
Release milestone dates:
https://github.com/zephyrproject-rtos/zephyr/wiki/Release-Management
Release process:
https://docs.zephyrproject.org/latest/project/release_process.html
Regards,
The release team.