PatchSiren cyber security CVE debrief
CVE-2026-19738 zephyrproject CVE debrief
Bluetooth Controller CIS Create procedures have a retained RX node leak and reachable assertion vulnerability. An attacker within radio range can exploit this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link. This can lead to a denial of service or elevation of privileges. Defenders should prioritize verifying and applying patches for affected Zephyr versions and assess exposure in Bluetooth-enabled systems. The vulnerability is caused by the Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retaining an RX node, which can later be reused. However, in certain scenarios, this retained node is
- Vendor
- zephyrproject
- Product
- zephyr
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Bluetooth-enabled systems, particularly those using Zephyr versions 3.4.0 up to but not including 4.5.0, should assess exposure and prioritize patching. This includes operators, platform administrators, vulnerability management teams, and security teams. They should verify and apply patches, assess exposure, and monitor for unusual activity.
Why it matters
CVE-2026-19738 is a medium-severity vulnerability in Zephyr's Bluetooth Controller CIS Create procedures. An attacker within radio range can exploit this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link, potentially leading to a denial of service or elevation of privileges. Defenders should prioritize verifying and applying patches for affected Zephyr versions and assess exposure in Bluetooth-enabled systems.
- Potential denial of service due to memory leak
- Possible elevation of privileges through reachable assertion
- Need for verification of patch application and system exposure
- Potential for disruption of Bluetooth services
Technical summary
The Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retains an RX node, which can later be reused. However, in certain scenarios, this retained node is not released, leading to a memory leak and potential reachable assertion. An attacker within radio range can exploit this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link, potentially leading to a denial of service or elevation of privileges. The vulnerability affects Zephyr versions 3.4.0 up to but not including 4.5.0.
Defensive priority
Defenders should prioritize verifying and applying patches for Zephyr versions 3.4.0 up to but not including 4.5.0, and assess exposure in Bluetooth-enabled systems.
Recommended defensive actions
- Verify and apply patches for Zephyr versions 3.4.0 up to but not including 4.5.0
- Assess exposure in Bluetooth-enabled systems
- Monitor for unusual LL Control PDU activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to patches and advisories. The vulnerability affects Zephyr versions 3.4.0 up to but not including 4.5.0. The CVE record was published on 2026-10-11T17:15:04.970Z and has not been modified since then. There are patches and advisories available for the affected versions. Defenders should verify and apply these patches and assess exposure in Bluetooth-enabled systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19738 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19738
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19738 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19738
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Retained RX node leak and reachable assertion in Bluetooth Controller CIS Create procedures
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19738.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/commit/fde17f2c3de0118f3796c2a83958ee4ce4b5efd6
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-6mcj-5jw8-ff36
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.