{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-19738", "assignerOrgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "state": "PUBLISHED", "assignerShortName": "zephyr", "dateReserved": "2026-08-13T13:46:29.882Z", "datePublished": "2026-10-11T17:15:04.970Z", "dateUpdated": "2026-10-11T17:15:04.970Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "shortName": "zephyr", "dateUpdated": "2026-10-11T17:15:04.970Z" }, "title": "Retained RX node leak and reachable assertion in Bluetooth Controller CIS Create procedures", "descriptions": [ { "lang": "en", "value": "The Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retains an RX node (ctx->node_ref.rx, marked NODE_RX_TYPE_RETAIN) so it can later be reused as the host notification — on the peripheral while awaiting the Host's reply to an LL_CIS_REQ, and on the central for the whole duration of a locally initiated CIS Create. In subsys/bluetooth/controller/ll_sw/ull_llcp_cc.c, the \"invalid PDU received\" paths of llcp_rp_cc_rx() and llcp_lp_cc_rx() terminated the connection and completed the procedure without releasing that retained node, breaking the invariant checked in llcp_lr_check_done() and llcp_rr_check_done() and orphaning the node's memory.\n\nA peer device within radio range can reach this with a single extra LL Control PDU on an unauthenticated, unencrypted ACL link. Against a peripheral, the attacker sends a valid LL_CIS_REQ and then, before the Host replies, any unrelated LL Control PDU (for example LL_VERSION_IND), which ull_cp_rx() routes into the active remote procedure. Against a central performing a CIS Create, a malicious peripheral answers with LL_UNKNOWN_RSP for CIS_REQ, which is dispatched into the active local procedure. No pairing, encryption or user interaction is required; the code is compiled in when CONFIG_BT_CTLR_PERIPHERAL_ISO or CONFIG_BT_CTLR_CENTRAL_ISO is enabled.\n\nIn default builds (CONFIG_BT_CTLR_ASSERT_DEBUG is default y) the retained-node assertion fires immediately, producing a controller fatal error and, typically, a system reset from one injected PDU. With the development assertions disabled, each attempt permanently loses one node from the controller's small LL notification pool (LL_PDU_RX_CNT, 2 * CONFIG_BT_CTLR_LLCP_CONN) together with its memq_link_t; repeating the connect-attack-reconnect cycle exhausts the pool, after which notification allocation always fails, RX flow control stalls, and the non-disableable LL_ASSERT_ERR() in llcp_lp_cc_flush() faults. The impact is limited to availability — the leaked node is orphaned, never reused or double-freed — and recovery requires a reboot." } ], "affected": [ { "vendor": "zephyrproject", "product": "zephyr", "collectionURL": "https://github.com/zephyrproject-rtos/zephyr", "packageName": "zephyr", "defaultStatus": "unaffected", "programFiles": [ "subsys/bluetooth/controller/ll_sw/ull_llcp_cc.c" ], "programRoutines": [ { "name": "llcp_lp_cc_rx" }, { "name": "llcp_rp_cc_rx" } ], "versions": [ { "version": "3.4.0", "status": "affected", "lessThan": "4.5.0", "versionType": "semver" } ] } ], "references": [ { "url": "https://github.com/zephyrproject-rtos/zephyr/commit/fde17f2c3de0118f3796c2a83958ee4ce4b5efd6", "name": "Fix commit", "tags": [ "patch" ] }, { "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-6mcj-5jw8-ff36", "name": "GHSA-6mcj-5jw8-ff36" } ], "metrics": [ { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM" } } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "dos", "cweId": "CWE-401", "type": "CWE" } ] } ], "x_generator": { "engine": "cvelib 1.8.0" } } } }