PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19935 zephyrproject CVE debrief

A use-after-free vulnerability exists in the Zephyr Bluetooth host when handling L2CAP connection-oriented channels. An unauthenticated remote peer can trigger this by sending a data K-frame followed by a Disconnect Request, potentially leading to a crash or code execution. The vulnerability arises from the host's failure to cancel the RX work item on L2CAP CoC channel teardown, allowing the channel object to be accessed after it has been freed. This issue affects Zephyr-based Bluetooth devices, particularly those using dynamic PSMs.

Vendor
zephyrproject
Product
zephyr
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Zephyr-based Bluetooth devices, particularly those using dynamic PSMs, should assess exposure and apply patches or compensating controls. This includes teams managing IoT devices, automotive systems, and other Zephyr-based platforms that utilize Bluetooth connectivity. Security teams should prioritize patching and monitoring for unusual activity to prevent potential system crashes or code execution.

Why it matters

CVE-2026-19935 is a high-severity use-after-free vulnerability in the Zephyr Bluetooth host. Defenders of Zephyr-based Bluetooth devices, especially those using dynamic PSMs, should assess exposure and apply patches or compensating controls to prevent potential system crashes or code execution. Evidence is limited, so verification of exploitation and impact is needed.

  • Potential system crash or instability
  • Possible code execution requiring verification
  • Need for patch application or compensating controls
  • Requires monitoring for unusual Bluetooth activity

Technical summary

The Zephyr Bluetooth host does not cancel the RX work item on L2CAP CoC channel teardown, allowing a use-after-free vulnerability. An unauthenticated remote peer can trigger this by sending a data K-frame followed by a Disconnect Request. The vulnerability arises from the host's failure to cancel the RX work item, which is submitted to the system workqueue, while HCI receive processing runs on the dedicated Bluetooth RX workqueue. This can lead to a crash or potential code execution if the channel object is accessed after it has been freed.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch from https://github.com/zephyrproject-rtos/zephyr/commit/22896cb8d6f23feffe4b637119fb3e974ac3bed8
  • Assess exposure and apply compensating controls for Zephyr versions 2.0.0 through 4.4.2
  • Monitor for unusual Bluetooth activity
  • Verify the patch has been applied and test for vulnerability
  • Review system logs for signs of exploitation
  • Update asset inventory to reflect affected systems
  • Consider rollback or change windows for remediation

Evidence notes

The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploits or impacts. Evidence is limited, so verification of exploitation and impact is needed. The vulnerability was publicly disclosed on 2026-10-11T17:15:03.386Z. The source item and CVE record provide the primary details, but additional research may be required to fully understand the vulnerability and its potential impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19935 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19935

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19935 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19935

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.