CVE-2026-15894
Received Received - Intake

Buffer Overflow in Zephyr Bluetooth Mesh Solicitation Handler

Vulnerability report for CVE-2026-15894, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Zephyr Project

Description

The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out, in->data, in->len); net_buf_simple_add() guards its tailroom only with __ASSERT_NO_MSG, which is compiled out in production builds, so when in->len > 17 the underlying memcpy writes attacker-controlled bytes past the 17-byte stack buffer. The copy occurs before any decryption or authentication, so no key material is required to trigger it. The oversized length arises because the mesh scan callback in subsys/bluetooth/mesh/adv.c calls net_buf_simple_restore() before dispatching to bt_mesh_sol_recv(), leaving buf->len covering the entire remaining advertising payload rather than just the Solicitation Service Data. After the parser locates the Service Data AD and consumes the Identification Type byte, the remaining buf->len is the 17-octet Network PDU plus any trailing advertising bytes, and prior to this fix there was no maximum-length check (only a minimum). An attacker can therefore append extra AD structures or padding after the Solicitation Service Data to make buf->len exceed 17. bt_mesh_scan_cb() is registered directly as the BLE scan callback, so buf is raw, unauthenticated advertising data received over the air. Any device in radio range can send a non-connectable advertisement carrying a crafted mesh Proxy Solicitation to a node that has CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and is currently eligible to be solicited (GATT proxy disabled, On-Demand Private Proxy enabled), with no pairing, bonding, or provisioning. The result is an attacker-controlled stack overwrite β€” plausibly leading to remote code execution and at minimum a reliable remote denial of service. The fix trims buf->len to the spec-fixed 17 octets (dropping the PDU if fewer remain) before decryption.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 3.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack buffer overflow in Zephyr RTOS's Bluetooth Mesh On-Demand Private Proxy. A fixed 17-byte stack buffer is used to copy a received Solicitation PDU without checking its length. The scan callback includes extra advertising data beyond the Solicitation Service Data, allowing an attacker to craft oversized packets that overflow the buffer before decryption or authentication.

Detection Guidance

To detect this vulnerability, check if your Zephyr RTOS device has CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and is running a vulnerable version (3.4.0 to 4.4.1). Monitor for unexpected crashes or memory corruption during Bluetooth Mesh operations. Use network sniffing tools to inspect Bluetooth advertisements for oversized Solicitation PDUs.

Impact Analysis

An attacker within radio range can send a crafted advertisement to trigger a stack overwrite. This may lead to remote code execution or at minimum a reliable denial of service. No authentication, pairing, or provisioning is required. The attack works if the device has CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and the GATT proxy is disabled.

Compliance Impact

This vulnerability could lead to unauthorized code execution or data access, violating confidentiality and integrity requirements in GDPR and HIPAA. Remote code execution may result in data breaches or unauthorized system access, posing significant compliance risks.

Mitigation Strategies

Immediately update Zephyr RTOS to version 4.4.2 or later. Disable CONFIG_BT_MESH_OD_PRIV_PROXY_SRV if not required. Ensure Bluetooth Mesh devices are not in radio range of untrusted sources. Monitor for suspicious Bluetooth traffic patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15894. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart