CWE-666: Operation on Resource in Wrong Phase of Lifetime
The product performs an operation on a resource at the wrong phase of the resource's lifecycle, which can lead to unexpected behaviors.
2 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-68930 — Russh: Channel-scoped server callbacks can be reached without an open channel
- CVE-2026-15460 — Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path
Recently published
- CVE-2026-15460 — Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path
- CVE-2026-68930 — Russh: Channel-scoped server callbacks can be reached without an open channel