Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yoctoproject

First CVE: Jun 16, 2017Active for: 9 yearsTotal CVEs: 27
21.3
VTI Score
Low

Yoctoproject is a build framework and embedded Linux distribution that serves as a foundation for custom Linux systems across diverse embedded and IoT devices, and its vulnerability footprint reflects the complexity of component integration rather than endemic flaws in a single product. The exposure concentrates in the Yocto core and its Pyro release branch and recurs through weakness classes including out-of-bounds writes, integer overflows, out-of-bounds reads, type confusion, and input validation issues—patterns that typically originate in third-party libraries and toolchain components bundled during the build process. Because Yoctoproject's role is to compose and customize Linux distributions rather than provide a monolithic product, vulnerabilities here often surface as inherited issues from embedded codebases and cross-compilation toolchains rather than defects intrinsic to the framework itself. Defenders tracking Yocto-based deployments should focus on the composition of upstream components in their builds and the recurrence of memory-safety and type-handling issues in compiled binaries rather than treating Yocto disclosures as uniformly critical. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yoctoproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2017
9 years ago
Most Recent CVE
May 15, 2023
1,166 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-26447CRITICAL
In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User
Sep 6, 20229.830NONO
CVE-2017-9731HIGH
In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Sourc
Jun 16, 20177.524NONO
CVE-2022-32633MEDIUM
In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interacti
Dec 5, 20226.722NONO
CVE-2022-32632MEDIUM
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i
Dec 5, 20226.722NONO
CVE-2022-32631MEDIUM
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i
Dec 5, 20226.722NONO
CVE-2022-26465MEDIUM
In audio ipi, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. Us
Sep 6, 20226.722NONO
CVE-2022-26435MEDIUM
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio
Aug 1, 20226.722NONO
CVE-2022-26433MEDIUM
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio
Aug 1, 20226.722NONO
CVE-2022-26431MEDIUM
In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User in
Aug 1, 20226.722NONO
CVE-2022-26430MEDIUM
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio
Aug 1, 20226.722NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
93%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local25 (92.6%)
Network2 (7.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None27 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High25 (92.6%)
None2 (7.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yoctoproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yoctoproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yoctoproject's Products

View all 2 CNAs →

Top CWEs