Bluetooth Link Layer Vulnerability in Zephyr Project
CVE-2026-19739
6.5MEDIUM
What is CVE-2026-19739?
The Bluetooth Link Layer control procedure within the Zephyr Project contains a vulnerability that can be exploited by a peer device within radio range, without requiring pairing or encryption. By sending a well-formed LL_CONNECTION_UPDATE_IND followed by other LL Control PDUs, an attacker can trigger a condition that exhausts the controller's RX buffer pool, leading to a denial of service. With CONFIG_BT_CTLR_ASSERT_DEBUG enabled, the vulnerability results in an immediate fatal error, while disabling it allows for repeated exploitation until the buffer is exhausted. This attack does not involve memory disclosure or corruption, but instead leads to persistent service disruption requiring a device reboot.
Affected Version(s)
zephyr 3.4.0 < 4.5.0
