PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19738 zephyrproject CVE debrief

Bluetooth Controller CIS Create procedures have a retained RX node leak and reachable assertion vulnerability. An attacker within radio range can exploit this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link. This can lead to a denial of service or elevation of privileges. Defenders should prioritize verifying and applying patches for affected Zephyr versions and assess exposure in Bluetooth-enabled systems. The vulnerability is caused by the Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retaining an RX node, which can later be reused. However, in certain scenarios, this retained node is

Vendor
zephyrproject
Product
zephyr
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Bluetooth-enabled systems, particularly those using Zephyr versions 3.4.0 up to but not including 4.5.0, should assess exposure and prioritize patching. This includes operators, platform administrators, vulnerability management teams, and security teams. They should verify and apply patches, assess exposure, and monitor for unusual activity.

Why it matters

CVE-2026-19738 is a medium-severity vulnerability in Zephyr's Bluetooth Controller CIS Create procedures. An attacker within radio range can exploit this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link, potentially leading to a denial of service or elevation of privileges. Defenders should prioritize verifying and applying patches for affected Zephyr versions and assess exposure in Bluetooth-enabled systems.

  • Potential denial of service due to memory leak
  • Possible elevation of privileges through reachable assertion
  • Need for verification of patch application and system exposure
  • Potential for disruption of Bluetooth services

Technical summary

The Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retains an RX node, which can later be reused. However, in certain scenarios, this retained node is not released, leading to a memory leak and potential reachable assertion. An attacker within radio range can exploit this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link, potentially leading to a denial of service or elevation of privileges. The vulnerability affects Zephyr versions 3.4.0 up to but not including 4.5.0.

Defensive priority

Defenders should prioritize verifying and applying patches for Zephyr versions 3.4.0 up to but not including 4.5.0, and assess exposure in Bluetooth-enabled systems.

Recommended defensive actions

  • Verify and apply patches for Zephyr versions 3.4.0 up to but not including 4.5.0
  • Assess exposure in Bluetooth-enabled systems
  • Monitor for unusual LL Control PDU activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to patches and advisories. The vulnerability affects Zephyr versions 3.4.0 up to but not including 4.5.0. The CVE record was published on 2026-10-11T17:15:04.970Z and has not been modified since then. There are patches and advisories available for the affected versions. Defenders should verify and apply these patches and assess exposure in Bluetooth-enabled systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19738 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19738

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19738 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19738

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.