CVE-2026-19935
Received Received - Intake

Use-After-Free in Zephyr RTOS Bluetooth LE L2CAP

Vulnerability report for CVE-2026-19935, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_process()) whenever the channel uses a dynamic PSM (0x0080-0x00FF). Channel teardown in l2cap_chan_destroy() in subsys/bluetooth/host/l2cap.c cancels the retransmission-timeout work and drains the RX FIFO, but never cancels rx_work. Because that work item was submitted to the system workqueue while HCI receive processing runs on the dedicated Bluetooth RX workqueue (CONFIG_BT_RECV_WORKQ_BT, the default), a queued rx_work item can outlive the channel it points into. A remote, unauthenticated peer with an established CoC channel triggers this by sending a data K-frame immediately followed by an L2CAP Disconnect Request. The K-frame submits rx_work to the system workqueue; because both workqueue threads are cooperative and the Bluetooth RX workqueue runs at the higher priority (K_PRIO_COOP(CONFIG_BT_RX_PRIO) versus CONFIG_SYSTEM_WORKQUEUE_PRIORITY), the pending item cannot run before the following Disconnect Request is processed in le_disconn_req() -> l2cap_chan_del() -> l2cap_chan_destroy(). The stack then invokes the released() callback, which the API documents as meaning the stack has dropped all references and the application may free the channel memory. The application therefore frees or re-accepts into an object that the system workqueue still holds in its pending list. If the memory is freed and reallocated, the workqueue later dereferences a list node and a handler function pointer read from reused memory; if the object is re-used for a later connection, l2cap_chan_add() calls k_work_init() on a still-enqueued work item, corrupting the workqueue's pending list so that unrelated work items are dropped or the queue spins on a looped list. A related variant lets l2cap_rx_process() run concurrently with teardown, racing the net_buf unref of le_chan->_sdu and the clearing of chan->conn. The fix routes the channel RX work to the Bluetooth workqueue - the same context in which every teardown path runs - and adds an explicit k_work_cancel() of le_chan->rx_work in l2cap_chan_destroy(), so no reference to the channel survives the released() callback. Configurations without CONFIG_BT_L2CAP_DYNAMIC_CHANNEL, or that only use SIG-assigned PSMs (EATT 0x0027, OTS 0x0025) which take the inline receive path, are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Zephyr RTOS Bluetooth host stack affecting L2CAP Connection-Oriented Channel (CoC) objects. The issue occurs because the RX work item for deferred processing of received data is not cancelled during channel teardown. A remote attacker can exploit this by sending a data frame followed by a disconnect request, causing the work item to outlive the channel object it references. When the system workqueue later processes the work item, it may dereference freed memory or corrupt the workqueue's pending list.

Detection Guidance

This vulnerability is specific to Zephyr RTOS Bluetooth host stack implementations using dynamic PSMs (0x0080-0x00FF). Detection requires checking Zephyr RTOS version and Bluetooth configuration. Use commands like 'git log --oneline' in Zephyr source to verify if the fix commit 22896cb8d6f23feffe4b637119fb3e974ac3bed8 is applied. Check Bluetooth configuration for CONFIG_BT_L2CAP_DYNAMIC_CHANNEL=y and dynamic PSM usage.

Impact Analysis

An attacker could exploit this to cause a denial of service, execute arbitrary code, or escalate privileges on a device running vulnerable Zephyr RTOS versions. The impact includes potential crashes, memory corruption, or unauthorized access if the freed memory is reallocated for malicious purposes.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized memory access or data corruption in Bluetooth LE devices running Zephyr RTOS. Exploitation may lead to data breaches or integrity violations, which are critical concerns under these regulations.

Mitigation Strategies

Apply the official patch from Zephyr Project by updating to a version that includes commit 22896cb8d6f23feffe4b637119fb3e974ac3bed8. Disable dynamic PSM usage if not required. Ensure Bluetooth workqueue synchronization is properly configured. Monitor for unusual Bluetooth stack behavior or crashes indicating potential exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19935. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart