Bluetooth Link Layer Vulnerability in Zephyr RTOS
CVE-2026-19738
6.5MEDIUM
What is CVE-2026-19738?
The Bluetooth Link Layer implementation in Zephyr RTOS has a vulnerability in the management of node references during Connected Isochronous Stream (CIS) creation. When a valid LL_CIS_REQ is received, subsequent unrelated LL Control PDUs can manipulate the connection process, leading to unexpected behavior. This flaw can allow an attacker to exploit a retained node reference on the controller, disrupting normal operations. Under certain conditions, this may cause a system reset, impacting the availability of the device. While the leaked node is not double-freed and does not pose a direct data breach, it can result in significant denial-of-service impacts, with recovery requiring a reboot.
Affected Version(s)
zephyr 3.4.0 < 4.5.0
