Yoctoproject is a build framework and embedded Linux distribution that serves as a foundation for custom Linux systems across diverse embedded and IoT devices, and its vulnerability footprint reflects the complexity of component integration rather than endemic flaws in a single product. The exposure concentrates in the Yocto core and its Pyro release branch and recurs through weakness classes including out-of-bounds writes, integer overflows, out-of-bounds reads, type confusion, and input validation issues—patterns that typically originate in third-party libraries and toolchain components bundled during the build process. Because Yoctoproject's role is to compose and customize Linux distributions rather than provide a monolithic product, vulnerabilities here often surface as inherited issues from embedded codebases and cross-compilation toolchains rather than defects intrinsic to the framework itself. Defenders tracking Yocto-based deployments should focus on the composition of upstream components in their builds and the recurrence of memory-safety and type-handling issues in compiled binaries rather than treating Yocto disclosures as uniformly critical. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yoctoproject over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26447CRITICAL In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User | Sep 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2017-9731HIGH In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Sourc | Jun 16, 2017 | 7.5 | 24 | NO | NO |
CVE-2022-32633MEDIUM In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interacti | Dec 5, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-32632MEDIUM In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i | Dec 5, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-32631MEDIUM In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i | Dec 5, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26465MEDIUM In audio ipi, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. Us | Sep 6, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26435MEDIUM In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio | Aug 1, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26433MEDIUM In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio | Aug 1, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26431MEDIUM In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User in | Aug 1, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26430MEDIUM In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio | Aug 1, 2022 | 6.7 | 22 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yoctoproject.
Media articles that mention a CVE ID that affects a product developed by Yoctoproject — matched by CVE ID, not by vendor name.