Memory Corruption Vulnerability in Bluetooth Classic by Zephyr Project
CVE-2026-10680

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-10680?

An issue in the Bluetooth Classic L2CAP signaling handlers in Zephyr allows attackers to exploit improper command size validation, leading to memory corruption. By sending crafted requests, an unauthenticated attacker within radio range can cause out-of-bounds memory access, potentially resulting in device crashes or denial of service. This vulnerability affects devices running impacted versions of Zephyr, emphasizing the importance of updating to the fixed versions that ensure proper checks against command length.

Affected Version(s)

zephyr 4.2.0 < 4.3.1

zephyr 4.4.0 <= 4.4.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.