PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19739 zephyrproject CVE debrief

The Bluetooth LE controller in Zephyr project versions prior to 4.5.0 is vulnerable to a retained RX node leak when an unexpected LL Control PDU arrives during a Connection Update. This issue, identified as CVE-2026-19739, can be exploited by a peer device in radio range without the need for pairing, bonding, or encryption. The vulnerability stems from the Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c, which retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant. Defenders should review and apply patches, update to Zephyr version 4.5.0 or later, and monitor Bluetooth LE to

Vendor
zephyrproject
Product
zephyr
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Bluetooth LE device manufacturers and users, Zephyr project developers and users, security teams responsible for monitoring and mitigating vulnerabilities in Bluetooth LE devices, and operators of systems that utilize Zephyr-based Bluetooth LE components should be aware of this vulnerability and take necessary actions to mitigate it.

Why it matters

CVE-2026-19739 is a medium-severity vulnerability in the Zephyr Bluetooth LE controller that can cause a retained RX node leak when an unexpected LL Control PDU arrives during a Connection Update. This vulnerability can be exploited by a peer device in radio range without pairing, bonding, or encryption. Defenders should review and apply patches, update to Zephyr version 4.5.0 or later, and monitor Bluetooth LE communications for unusual activity.

  • Verify and apply patches to prevent RX node leaks
  • Monitor Bluetooth LE communications for unusual activity
  • Update to Zephyr version 4.5.0 or later

Technical summary

The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant. A peer device in radio range can reach this without pairing, bonding, or encryption. The default: arm of llcp_rp_cu_rx() and llcp_lp_cu_rx() — the 'invalid PDU, terminate the connection' path — completed the procedure without releasing that retained node. llcp_rr_check_done() then dequeued and freed the procedure context with ctx->node_ref.rx still pointing at the retained node, dropping the last reference to it.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the patch from https://github.com/zephyrproject-rtos/zephyr/commit/7b600129faaba8bb26dd5cb3e8f17ed1cb41ea7f
  • Update to Zephyr version 4.5.0 or later
  • Monitor Bluetooth LE communications for unusual activity
  • Verify the patch has been applied and test the system
  • Conduct a thorough review of the Bluetooth LE communications for any suspicious activity
  • Consider implementing compensating controls for exposed systems
  • Track exceptions and retest remediated assets

Evidence notes

The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant. A peer device in radio range can reach this without pairing, bonding, or encryption.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19739 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19739

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19739 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19739

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.