MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 17 h ago, last 17 h ago, peak #12

Zephyr RTOS vulnerability risks nonce reuse in encrypted storage

Original: CVE-2026-15890 Zephyr: unsynchronized static nonce counter in the ITS AEAD transform. Concurrent writes can reuse an AES

A new vulnerability, CVE-2026-15890, has been disclosed in the Zephyr operating system's ITS AEAD transform. The static nonce counter is not synchronized, so concurrent writes can reuse an AES-GCM or ChaCha20-Poly1305 nonce, potentially compromising data integrity. The flaw carries a CVSS score of 5.3, and a patch is reportedly under review.

Why now: Security researchers are highlighting a freshly disclosed CVE in the widely used Zephyr RTOS while its fix is still pending.

ZephyrCVE-2026-15890AES-GCMChaCha20-Poly1305

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/377994