CVE-2026-19570
Received Received - Intake

Buffer Overflow in LE Audio Broadcast Sink

Vulnerability report for CVE-2026-19570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Zephyr Project

Description

The LE Audio Broadcast Sink in subsys/bluetooth/audio/bap_broadcast_sink.c copies subgroup metadata from a received Basic Audio Announcement (BASE) into the static Broadcast Audio Scan Service parameter structure mod_src_param without any bounds check. In base_subgroup_meta_cb() the destination element was selected as mod_src_param.subgroups[mod_src_param.num_subgroups] with no test against ARRAY_SIZE(mod_src_param.subgroups) (sized by CONFIG_BT_BAP_BASS_MAX_SUBGROUPS, default 1), and the metadata was copied with memcpy() using the raw on-air length returned by bt_bap_base_get_subgroup_codec_meta() into a metadata array sized by CONFIG_BT_AUDIO_CODEC_CFG_MAX_METADATA_SIZE (default 4). The BASE validator bt_bap_base_get_base_from_ad() only checks structural consistency and permits up to ~24 subgroups and metadata LTVs of ~240 octets. The defect is reached from the periodic advertising receive callback: pa_recv() β†’ bt_data_parse() β†’ pa_decode_base() β†’ update_recv_state_base() β†’ bt_bap_base_foreach_subgroup() β†’ base_subgroup_meta_cb(). Every broadcast sink registers a scan-delegator receive state at creation (bt_bap_broadcast_sink_create() calls broadcast_sink_add_src()), and CONFIG_BT_BAP_BROADCAST_SINK depends on CONFIG_BT_BAP_SCAN_DELEGATOR, so the path is active in every broadcast-sink build once the device is periodic-advertising-synced. An attacker in radio range who operates a broadcast source the device syncs to β€” or who impersonates the advertiser address and SID of one already in use, periodic advertising data being unauthenticated β€” can change the BASE at will; each new BASE is re-parsed. A crafted BASE therefore writes attacker-chosen bytes past the end of a fixed static object in .bss: up to roughly 236 bytes for an oversized metadata LTV, plus whole struct bt_bap_bass_subgroup records for each subgroup beyond CONFIG_BT_BAP_BASS_MAX_SUBGROUPS. This is memory corruption of adjacent Bluetooth-audio state reachable with no pairing, bonding or GATT connection, with a potential for remote code execution in the Bluetooth RX thread; in addition, the unvalidated metadata_len is forwarded to bt_bap_scan_delegator_mod_src(), which neither clamps it nor rejects it, leading to a further copy into the receive state and to out-of-bounds memory being disclosed in the BASS receive-state notification sent to a connected Broadcast Assistant. The fix rejects a BASE carrying more subgroups than the receive state can hold (discarding the update entirely) and omits metadata that does not fit rather than copying it, and additionally honours the previously-ignored error return of the subgroup decode pass.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 3.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds write vulnerability in the LE Audio Broadcast Sink of Zephyr RTOS. When processing a Basic Audio Announcement (BASE), subgroup metadata is copied without bounds checking into a fixed-size buffer. An attacker within radio range can send a maliciously crafted BASE to trigger memory corruption in adjacent Bluetooth-audio state, potentially leading to remote code execution in the Bluetooth RX thread.

Detection Guidance

This vulnerability is specific to Zephyr RTOS devices using LE Audio Broadcast Sink functionality. Detection requires checking if your device runs a vulnerable Zephyr RTOS version (prior to 4.5.0 or backported fixes for 3.7, 4.3, 4.4). Inspect Bluetooth stack logs for memory corruption errors or BASE parsing failures. Monitor for unexpected Bluetooth RX thread crashes or BASS notifications with invalid metadata lengths.

Impact Analysis

An attacker in radio range can exploit this to corrupt memory in Bluetooth audio devices like hearing aids, earbuds, speakers, or TVs acting as Auracast receivers. This may allow remote code execution in the Bluetooth RX thread, potentially taking control of the device or causing crashes. No pairing, bonding, or GATT connection is required for exploitation.

Mitigation Strategies

Update Zephyr RTOS to version 4.5.0 or apply backported fixes for 3.7, 4.3, or 4.4 branches. Disable LE Audio Broadcast Sink functionality if not required. Ensure Bluetooth periodic advertising synchronization is restricted to trusted sources only. Monitor for suspicious BASE updates or metadata anomalies in Bluetooth logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart