CVE-2026-19738
Received Received - Intake

Bluetooth Controller Memory Leak in Zephyr RTOS

Vulnerability report for CVE-2026-19738, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retains an RX node (ctx->node_ref.rx, marked NODE_RX_TYPE_RETAIN) so it can later be reused as the host notification β€” on the peripheral while awaiting the Host's reply to an LL_CIS_REQ, and on the central for the whole duration of a locally initiated CIS Create. In subsys/bluetooth/controller/ll_sw/ull_llcp_cc.c, the "invalid PDU received" paths of llcp_rp_cc_rx() and llcp_lp_cc_rx() terminated the connection and completed the procedure without releasing that retained node, breaking the invariant checked in llcp_lr_check_done() and llcp_rr_check_done() and orphaning the node's memory. A peer device within radio range can reach this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link. Against a peripheral, the attacker sends a valid LL_CIS_REQ and then, before the Host replies, any unrelated LL Control PDU (for example LL_VERSION_IND), which ull_cp_rx() routes into the active remote procedure. Against a central performing a CIS Create, a malicious peripheral answers with LL_UNKNOWN_RSP for CIS_REQ, which is dispatched into the active local procedure. No pairing, encryption or user interaction is required; the code is compiled in when CONFIG_BT_CTLR_PERIPHERAL_ISO or CONFIG_BT_CTLR_CENTRAL_ISO is enabled. In default builds (CONFIG_BT_CTLR_ASSERT_DEBUG is default y) the retained-node assertion fires immediately, producing a controller fatal error and, typically, a system reset from one injected PDU. With the development assertions disabled, each attempt permanently loses one node from the controller's small LL notification pool (LL_PDU_RX_CNT, 2 * CONFIG_BT_CTLR_LLCP_CONN) together with its memq_link_t; repeating the connect-attack-reconnect cycle exhausts the pool, after which notification allocation always fails, RX flow control stalls, and the non-disableable LL_ASSERT_ERR() in llcp_lp_cc_flush() faults. The impact is limited to availability β€” the leaked node is orphaned, never reused or double-freed β€” and recovery requires a reboot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 3.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory leak in the Zephyr RTOS Bluetooth controller during Connected Isochronous Stream (CIS) creation. The Bluetooth Link Layer Control Procedure retains an RX node for host notification but fails to release it if an unexpected control packet arrives. This leaks memory from the controller's small notification pool, eventually causing system failures.

Detection Guidance

This vulnerability is specific to Zephyr RTOS Bluetooth controller implementations with CONFIG_BT_CTLR_PERIPHERAL_ISO or CONFIG_BT_CTLR_CENTRAL_ISO enabled. Detection requires checking Bluetooth controller logs for fatal errors or assertion failures during CIS creation procedures. Monitor for repeated connection failures or system resets after unexpected LL Control PDUs.

Impact Analysis

An attacker within radio range can send a malicious packet to trigger the leak. In default builds, this causes an immediate system crash. Without default settings, repeated attacks exhaust memory, stalling data flow and requiring a reboot to recover. The impact is limited to availability.

Compliance Impact

This vulnerability primarily impacts system availability by causing memory leaks in the Bluetooth controller, leading to denial of service conditions. It does not directly expose or leak sensitive data, so it is unlikely to directly violate GDPR or HIPAA data protection requirements. However, repeated exploitation could cause system instability or crashes, potentially disrupting services that handle personal or health data, indirectly affecting compliance.

Mitigation Strategies
  • Upgrade Zephyr RTOS to version 4.5.0 or later where the fix is included.
  • Disable CONFIG_BT_CTLR_PERIPHERAL_ISO and CONFIG_BT_CTLR_CENTRAL_ISO in Bluetooth controller configuration if CIS functionality is not required.
  • Apply the patch from commit fde17f2c3de0118f3796c2a83958ee4ce4b5efd6 to older versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19738. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart