Bluetooth Mesh Subnet Key Management Vulnerability in Zephyr by Nordic Semiconductor
CVE-2026-10774

2.4LOW

Key Information:

Status
Vendor
CVE Published:
2 August 2026

What is CVE-2026-10774?

A vulnerability in Zephyr's Bluetooth Mesh implementation relates to improper management of Private Beacon Keys, leading to potential exhaustion of PSA crypto key slots. When subnet keys are deleted or refreshed, the corresponding key slots are not properly destroyed. This may prevent devices from adding new subnets or completing key refresh operations, effectively crippling the network's functionality. The flaw is particularly critical in scenarios where multiple key management operations are performed, potentially causing disruptions until the device is rebooted. The fix ensures that key slots are properly managed by aligning import and destroy operations.

Affected Version(s)

zephyr 3.6.0 < 4.5.0

References

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.