The Yocto Project is a build framework and embedded Linux distribution system used to construct custom Linux images for embedded and IoT devices, with its core metadata and build tools (Pyro) representing the primary affected component. Documented vulnerabilities in this context center on information-disclosure weaknesses where sensitive configuration, credentials, or build artifacts become accessible to unauthorized parties—a risk inherent to build systems that aggregate diverse software components and configuration data. Current vulnerability counts, severity distribution, and any exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yocto Project over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26447CRITICAL In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User | Sep 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2017-9731HIGH In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Sourc | Jun 16, 2017 | 7.5 | 24 | NO | NO |
CVE-2022-32633MEDIUM In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interacti | Dec 5, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-32632MEDIUM In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i | Dec 5, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-32631MEDIUM In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i | Dec 5, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26465MEDIUM In audio ipi, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. Us | Sep 6, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26435MEDIUM In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio | Aug 1, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26433MEDIUM In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio | Aug 1, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26431MEDIUM In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User in | Aug 1, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26430MEDIUM In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio | Aug 1, 2022 | 6.7 | 22 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yocto Project.
Media articles that mention a CVE ID that affects a product developed by Yocto Project — matched by CVE ID, not by vendor name.