CVE-2026-19740
Received Received - Intake

Bluetooth LE Controller Use-After-Free in LLCP Procedure

Vulnerability report for CVE-2026-19740, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The Link Layer Control Procedure (LLCP) implementation of the Zephyr software Bluetooth LE Controller retains the receive node that carried an accepted LL_PHY_UPDATE_IND so that it can later be reused for the host notification when the update instant is reached (llcp_rx_node_retain() in subsys/bluetooth/controller/ll_sw/ull_llcp.c, and the node is deliberately not recycled while marked NODE_RX_TYPE_RETAIN). The invalid-PDU arms of llcp_lp_pu_rx() and llcp_rp_pu_rx() in subsys/bluetooth/controller/ll_sw/ull_llcp_phy.c completed the procedure via llcp_lr_complete() / llcp_rr_complete() without first releasing that retained node, so the procedure context β€” the only remaining reference to the node β€” was freed while the node was still held out of the receive pool. A peer device on an established LE connection can drive this deterministically and without pairing or encryption. Against a peripheral it sends LL_PHY_REQ, receives LL_PHY_RSP, sends a valid LL_PHY_UPDATE_IND with an instant a few connection events in the future (so the node becomes retained), and then, before the instant is reached, sends any other LL Control PDU such as LL_LENGTH_REQ; ull_cp_rx() routes it to the active remote PHY Update procedure, which takes the invalid-PDU path. The mirror case applies to a locally initiated PHY Update followed by an LL_REJECT_IND. In the default configuration (CONFIG_BT_ASSERT and CONFIG_BT_CTLR_ASSERT_DEBUG both default y) the violated invariant in llcp_lr_check_done() / llcp_rr_check_done() triggers a controller assertion, ending in k_oops() (or k_panic()) β€” a single crafted PDU sequence from radio range faults the device. With those assertions compiled out, each attempt silently leaks one receive PDU node and its memq link; because the controller receive pool is small (PDU_RX_CNT, driven by CONFIG_BT_CTLR_RX_BUFFERS, which defaults to 1) and each attempt costs the attacker only a reconnect, a few repetitions exhaust the pool and leave Bluetooth inoperable until reboot. On releases v3.4.0 through v3.7.x the assertion is never reached, whatever the configuration, so every attempt leaks silently. The impact is limited to availability: the orphaned node leaves no dangling pointer that is later dereferenced and is never delivered to the host, so there is no memory corruption or information disclosure. The same pull request applies the identical release to the Connection Update and CIS-create procedures, whose invalid-PDU arms had the same omission.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 3.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19740 is a memory leak vulnerability in the Zephyr RTOS Bluetooth LE Controller affecting versions 3.4.0 to 4.4.2. When a peer device initiates a PHY update, the controller retains an RX node for later notification. If an unexpected LL Control PDU arrives before the update instant, the procedure completes without releasing the node, causing a memory leak. In assert-enabled builds, this triggers a controller crash. Without assertions, repeated exploitation exhausts the RX node pool, making Bluetooth inoperable until reboot.

Detection Guidance

This vulnerability is specific to the Zephyr RTOS Bluetooth LE Controller and requires specialized BLE protocol analysis tools. There are no standard network or system commands to detect it directly. Monitoring for Bluetooth controller crashes or repeated connection drops may indicate exploitation attempts.

Impact Analysis

The vulnerability can cause Bluetooth inoperability due to RX node pool exhaustion, requiring a reboot to restore functionality. In assert-enabled builds, it may crash the device. No memory corruption or data disclosure occurs, and exploitation requires a connected BLE peer.

Compliance Impact

This vulnerability primarily impacts availability by causing Bluetooth inoperability due to RX node exhaustion, with no evidence of data disclosure or corruption. Standards like GDPR and HIPAA focus on data confidentiality, integrity, and availability; while this issue affects availability, it does not directly compromise data security or privacy. Compliance risks would arise only if the Bluetooth outage disrupts critical operations handling protected data.

Mitigation Strategies
  • Upgrade Zephyr RTOS to a patched version (v3.7.3 or later) to apply the fix for CVE-2026-19740.
  • Disable Bluetooth LE connections from untrusted devices until patched.
  • Monitor for Bluetooth controller crashes or connection failures as potential exploitation signs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19740. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart