PatchSiren cyber security CVE debrief
CVE-2026-19739 zephyrproject CVE debrief
The Bluetooth LE controller in Zephyr project versions prior to 4.5.0 is vulnerable to a retained RX node leak when an unexpected LL Control PDU arrives during a Connection Update. This issue, identified as CVE-2026-19739, can be exploited by a peer device in radio range without the need for pairing, bonding, or encryption. The vulnerability stems from the Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c, which retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant. Defenders should review and apply patches, update to Zephyr version 4.5.0 or later, and monitor Bluetooth LE to
- Vendor
- zephyrproject
- Product
- zephyr
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Bluetooth LE device manufacturers and users, Zephyr project developers and users, security teams responsible for monitoring and mitigating vulnerabilities in Bluetooth LE devices, and operators of systems that utilize Zephyr-based Bluetooth LE components should be aware of this vulnerability and take necessary actions to mitigate it.
Why it matters
CVE-2026-19739 is a medium-severity vulnerability in the Zephyr Bluetooth LE controller that can cause a retained RX node leak when an unexpected LL Control PDU arrives during a Connection Update. This vulnerability can be exploited by a peer device in radio range without pairing, bonding, or encryption. Defenders should review and apply patches, update to Zephyr version 4.5.0 or later, and monitor Bluetooth LE communications for unusual activity.
- Verify and apply patches to prevent RX node leaks
- Monitor Bluetooth LE communications for unusual activity
- Update to Zephyr version 4.5.0 or later
Technical summary
The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant. A peer device in radio range can reach this without pairing, bonding, or encryption. The default: arm of llcp_rp_cu_rx() and llcp_lp_cu_rx() — the 'invalid PDU, terminate the connection' path — completed the procedure without releasing that retained node. llcp_rr_check_done() then dequeued and freed the procedure context with ctx->node_ref.rx still pointing at the retained node, dropping the last reference to it.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the patch from https://github.com/zephyrproject-rtos/zephyr/commit/7b600129faaba8bb26dd5cb3e8f17ed1cb41ea7f
- Update to Zephyr version 4.5.0 or later
- Monitor Bluetooth LE communications for unusual activity
- Verify the patch has been applied and test the system
- Conduct a thorough review of the Bluetooth LE communications for any suspicious activity
- Consider implementing compensating controls for exposed systems
- Track exceptions and retest remediated assets
Evidence notes
The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant. A peer device in radio range can reach this without pairing, bonding, or encryption.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19739 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19739
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19739 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19739
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Bluetooth LE controller leaks a retained RX node when an unexpected LL Control PDU arrives durin
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19739.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/commit/7b600129faaba8bb26dd5cb3e8f17ed1cb41ea7f
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-84v8-vgp5-4vc9
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.