CVE-2026-15460
Awaiting Analysis Awaiting Analysis - Queue

Bluetooth Classic L2CAP Data Handling State Confusion

Vulnerability report for CVE-2026-15460, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: Zephyr Project

Description

The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target channel had reached the BT_L2CAP_CONNECTED state. A dynamic channel is assigned its RX CID and added to the connection's channel list while still in BT_L2CAP_CONNECTING (and later BT_L2CAP_CONFIG) β€” before configuration completes and, for PSMs that require security, before the peer is authenticated (l2cap_br_conn_req()). Because the channel is already findable by bt_l2cap_br_lookup_rx_cid() during this window, a remote peer within radio range can send a data PDU addressed to that CID and have it processed on a not-yet-established channel. The dispatch keys off channel fields (BR_CHAN(chan)->rx.mode, rx.mps) that are only initialized during configuration by l2cap_br_conf(); since channel objects are pooled and bt_l2cap_br_chan_del() does not reset rx.mode or the reassembly buffer _sdu, a reused channel can carry stale state into the CONNECTING window and route the frame into the retransmission/flow-control path (bt_l2cap_br_ret_fc_recv()) with stale parameters and a possibly stale _sdu pointer. The impact is delivery of attacker data to upper-layer protocol handlers on a half-open (and possibly unauthenticated) channel, plus operation on stale or partially initialized channel state on reused channel objects β€” leading to channel/link teardown (denial of service) and, in the stale-_sdu case, a dangling-pointer condition. The fix adds an explicit BR_CHAN(chan)->state < BT_L2CAP_CONNECTED guard that drops any data received before the channel is fully connected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-666 The product performs an operation on a resource at the wrong phase of the resource's lifecycle, which can lead to unexpected behaviors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Bluetooth Classic (BR/EDR) L2CAP receive handler in Zephyr OS. It allows a remote attacker within radio range to send data to a Bluetooth channel before it is fully connected and authenticated. The issue occurs because the system processes incoming data based solely on the channel ID without verifying if the channel is in a connected state. This can lead to data being delivered to upper-layer protocols on an unauthenticated channel and cause denial of service or dangling pointer issues due to stale channel state.

Detection Guidance

This vulnerability affects the Bluetooth Classic L2CAP receive handler in Zephyr OS. Detection requires checking for Bluetooth stack implementations using vulnerable Zephyr versions. Inspect Bluetooth logs for unexpected data PDUs on unconnected channels or channel state mismatches during connection setup.

Impact Analysis

An attacker could exploit this to send unauthorized data to your device over Bluetooth before the connection is fully established. This may result in denial of service, where the Bluetooth connection is terminated unexpectedly. In some cases, it could also lead to memory corruption due to stale data pointers, potentially causing system instability or crashes.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it pertains to Bluetooth Classic L2CAP data handling. However, potential unauthorized data access or denial of service could indirectly impact data integrity or availability, which are key considerations under these regulations.

Mitigation Strategies

Apply the official patch from Zephyr Project that adds the BT_L2CAP_CONNECTED state guard. Update to the latest Zephyr OS version. Disable Bluetooth Classic if not required. Monitor for unusual Bluetooth traffic patterns indicating exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15460. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart