{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-19739", "assignerOrgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "state": "PUBLISHED", "assignerShortName": "zephyr", "dateReserved": "2026-08-13T13:46:31.915Z", "datePublished": "2026-10-11T17:15:06.540Z", "dateUpdated": "2026-10-11T17:15:06.540Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "shortName": "zephyr", "dateUpdated": "2026-10-11T17:15:06.540Z" }, "title": "Bluetooth LE controller leaks a retained RX node when an unexpected LL Control PDU arrives during a Connection Update", "descriptions": [ { "lang": "en", "value": "The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant, so the node can later carry the host notification (llcp_rx_node_retain(), which marks it NODE_RX_TYPE_RETAIN and thereby suppresses the normal recycling in ull.c). The default: arm of llcp_rp_cu_rx() and llcp_lp_cu_rx() — the \"invalid PDU, terminate the connection\" path — completed the procedure without releasing that retained node. llcp_rr_check_done() then dequeued and freed the procedure context with ctx->node_ref.rx still pointing at the retained node, dropping the last reference to it.\n\nA peer device in radio range can reach this without pairing, bonding, or encryption. Against a peripheral, the peer sends a well-formed LL_CONNECTION_UPDATE_IND with an instant a few connection events in the future (the node is retained and the procedure enters RP_CU_STATE_WAIT_INSTANT), then, before the instant is reached, sends any other LL Control PDU such as LL_LENGTH_REQ. ull_cp_rx() routes that PDU into the active remote Connection Update procedure, which takes the invalid-PDU path. The central role is reachable symmetrically after accepting an LL_CONNECTION_PARAM_REQ, and the local-procedure variant is reachable with LL_REJECT_IND.\n\nWith CONFIG_BT_CTLR_ASSERT_DEBUG enabled (its default), the resulting state violates the invariant asserted in llcp_rr_check_done(), so the two-PDU sequence produces an immediate fatal error in the controller. With those asserts disabled, each occurrence permanently loses one node from the controller's small fixed RX pool (sized from CONFIG_BT_CTLR_RX_BUFFERS, which defaults to 1); repeating the sequence across reconnections exhausts the pool, after which the link-layer receive path operates on a NULL node. The impact is an unauthenticated, remotely triggerable denial of service persisting until reboot; there is no memory-disclosure or memory-corruption consequence, since the leaked node simply becomes unreachable." } ], "affected": [ { "vendor": "zephyrproject", "product": "zephyr", "collectionURL": "https://github.com/zephyrproject-rtos/zephyr", "packageName": "zephyr", "defaultStatus": "unaffected", "programFiles": [ "subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c" ], "programRoutines": [ { "name": "llcp_lp_cu_rx" }, { "name": "llcp_rp_cu_rx" } ], "versions": [ { "version": "3.4.0", "status": "affected", "lessThan": "4.5.0", "versionType": "semver" } ] } ], "references": [ { "url": "https://github.com/zephyrproject-rtos/zephyr/commit/7b600129faaba8bb26dd5cb3e8f17ed1cb41ea7f", "name": "Fix commit", "tags": [ "patch" ] }, { "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-84v8-vgp5-4vc9", "name": "GHSA-84v8-vgp5-4vc9" } ], "metrics": [ { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM" } } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "dos", "cweId": "CWE-401", "type": "CWE" }, { "lang": "en", "description": "dos", "cweId": "CWE-459", "type": "CWE" }, { "lang": "en", "description": "dos", "cweId": "CWE-617", "type": "CWE" }, { "lang": "en", "description": "dos", "cweId": "CWE-772", "type": "CWE" } ] } ], "x_generator": { "engine": "cvelib 1.8.0" } } } }