PatchSiren cyber security CVE debrief
CVE-2026-19935 zephyrproject CVE debrief
A use-after-free vulnerability exists in the Zephyr Bluetooth host when handling L2CAP connection-oriented channels. An unauthenticated remote peer can trigger this by sending a data K-frame followed by a Disconnect Request, potentially leading to a crash or code execution. The vulnerability arises from the host's failure to cancel the RX work item on L2CAP CoC channel teardown, allowing the channel object to be accessed after it has been freed. This issue affects Zephyr-based Bluetooth devices, particularly those using dynamic PSMs.
- Vendor
- zephyrproject
- Product
- zephyr
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Zephyr-based Bluetooth devices, particularly those using dynamic PSMs, should assess exposure and apply patches or compensating controls. This includes teams managing IoT devices, automotive systems, and other Zephyr-based platforms that utilize Bluetooth connectivity. Security teams should prioritize patching and monitoring for unusual activity to prevent potential system crashes or code execution.
Why it matters
CVE-2026-19935 is a high-severity use-after-free vulnerability in the Zephyr Bluetooth host. Defenders of Zephyr-based Bluetooth devices, especially those using dynamic PSMs, should assess exposure and apply patches or compensating controls to prevent potential system crashes or code execution. Evidence is limited, so verification of exploitation and impact is needed.
- Potential system crash or instability
- Possible code execution requiring verification
- Need for patch application or compensating controls
- Requires monitoring for unusual Bluetooth activity
Technical summary
The Zephyr Bluetooth host does not cancel the RX work item on L2CAP CoC channel teardown, allowing a use-after-free vulnerability. An unauthenticated remote peer can trigger this by sending a data K-frame followed by a Disconnect Request. The vulnerability arises from the host's failure to cancel the RX work item, which is submitted to the system workqueue, while HCI receive processing runs on the dedicated Bluetooth RX workqueue. This can lead to a crash or potential code execution if the channel object is accessed after it has been freed.
Defensive priority
High
Recommended defensive actions
- Review and apply the patch from https://github.com/zephyrproject-rtos/zephyr/commit/22896cb8d6f23feffe4b637119fb3e974ac3bed8
- Assess exposure and apply compensating controls for Zephyr versions 2.0.0 through 4.4.2
- Monitor for unusual Bluetooth activity
- Verify the patch has been applied and test for vulnerability
- Review system logs for signs of exploitation
- Update asset inventory to reflect affected systems
- Consider rollback or change windows for remediation
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploits or impacts. Evidence is limited, so verification of exploitation and impact is needed. The vulnerability was publicly disclosed on 2026-10-11T17:15:03.386Z. The source item and CVE record provide the primary details, but additional research may be required to fully understand the vulnerability and its potential impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19935 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19935
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19935 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19935
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Use-after-free of an L2CAP CoC channel object in the Zephyr Bluetooth host: RX work item is not
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19935.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/commit/22896cb8d6f23feffe4b637119fb3e974ac3bed8
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-6gp4-cwf7-2vp8
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.