Memory Corruption Vulnerability in LE Audio Broadcast Sink by Zephyr Project
CVE-2026-19570

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-19570?

The LE Audio Broadcast Sink in the Zephyr Project contains a vulnerability that allows an attacker within radio range to exploit the lack of bounds checking during the copying of subgroup metadata from a Basic Audio Announcement (BASE). The absence of checks leads to the possibility of memory corruption beyond allocated boundaries, which may allow for remote code execution within the Bluetooth RX thread. This issue can be triggered when a broadcast source with crafted BASE data is received, allowing an attacker to manipulate the device’s memory state without the need for pairing or bonding, thereby posing substantial risks to Bluetooth network integrity.

Affected Version(s)

zephyr 3.6.0 <= 4.4.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.