A vulnerability has been found in Zephyr Project Zephyr up to 4.4.1 and classified as very critical. Impacted is the function
flash_read/flash_write of the file drivers/flash/flash_sf32lb_mpi_qspi_nor.c of the component Flash Driver. Performing a manipulation of the argument offset/size results in signed to unsigned conversion error.
This vulnerability is reported as CVE-2026-11743. The attack requires a local approach. No exploit exists.
The affected component should be upgraded.