Description
The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out, in->data, in->len); net_buf_simple_add() guards its tailroom only with __ASSERT_NO_MSG, which is compiled out in production builds, so when in->len > 17 the underlying memcpy writes attacker-controlled bytes past the 17-byte stack buffer. The copy occurs before any decryption or authentication, so no key material is required to trigger it.

The oversized length arises because the mesh scan callback in subsys/bluetooth/mesh/adv.c calls net_buf_simple_restore() before dispatching to bt_mesh_sol_recv(), leaving buf->len covering the entire remaining advertising payload rather than just the Solicitation Service Data. After the parser locates the Service Data AD and consumes the Identification Type byte, the remaining buf->len is the 17-octet Network PDU plus any trailing advertising bytes, and prior to this fix there was no maximum-length check (only a minimum). An attacker can therefore append extra AD structures or padding after the Solicitation Service Data to make buf->len exceed 17.

bt_mesh_scan_cb() is registered directly as the BLE scan callback, so buf is raw, unauthenticated advertising data received over the air. Any device in radio range can send a non-connectable advertisement carrying a crafted mesh Proxy Solicitation to a node that has CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and is currently eligible to be solicited (GATT proxy disabled, On-Demand Private Proxy enabled), with no pairing, bonding, or provisioning. The result is an attacker-controlled stack overwrite — plausibly leading to remote code execution and at minimum a reliable remote denial of service. The fix trims buf->len to the spec-fixed 17 octets (dropping the PDU if fewer remain) before decryption.
Published: 2026-10-07
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack‑buffer overflow occurs in the Bluetooth Mesh On‑Demand Private Proxy solicitation handler when a received Solicitation PDU is copied into a fixed 17‑byte buffer without validating the source length. The overflow happens before decryption or authentication, so no key material is needed. An attacker can craft a non‑connectable BLE advertisement containing a malicious Solicitation PDU and arbitrary trailing advertising data, causing the device to overwrite the stack. The overwrite is plausibly exploitable for remote code execution and, at minimum, provides a reliable remote denial‑of‑service.

Affected Systems

The vulnerability affects devices running the Zephyr project’s Bluetooth Mesh stack with CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled. Firmware versions that have not applied the patch from commit 4416ad13677259d180f35ce44338578694e48184 (or earlier versions that contain the same code) are vulnerable; any device capable of receiving raw BLE advertising from an attacker in radio range is impacted. No specific product or version range is listed beyond the presence of the configuration flag.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and although the EPSS value is not available, the attack can be carried out by any nearby device without additional credentials. The vulnerability is not listed in the CISA KEV catalog. The absence of input validation and the use of an unsecured buffer make exploitation straightforward under normal operational conditions, making the risk significant. It is therefore critical to apply the official patch or upgrade to a fixed version as soon as possible.

Generated by OpenCVE AI on October 7, 2026 at 10:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zephyr patch containing commit 4416ad13677259d180f35ce44338578694e48184 or upgrade to a new Zephyr release that includes the fix.
  • Disable CONFIG_BT_MESH_OD_PRIV_PROXY_SRV in the Zephyr configuration if the On‑Demand Private Proxy service is not required for your deployment.
  • If an immediate firmware update is not feasible, restrict the device’s BLE scanning to only trusted proxies or block reception of all advertising PDUs that could trigger the vulnerable path by applying network or device‑level filtering.

Generated by OpenCVE AI on October 7, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Wed, 07 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out, in->data, in->len); net_buf_simple_add() guards its tailroom only with __ASSERT_NO_MSG, which is compiled out in production builds, so when in->len > 17 the underlying memcpy writes attacker-controlled bytes past the 17-byte stack buffer. The copy occurs before any decryption or authentication, so no key material is required to trigger it. The oversized length arises because the mesh scan callback in subsys/bluetooth/mesh/adv.c calls net_buf_simple_restore() before dispatching to bt_mesh_sol_recv(), leaving buf->len covering the entire remaining advertising payload rather than just the Solicitation Service Data. After the parser locates the Service Data AD and consumes the Identification Type byte, the remaining buf->len is the 17-octet Network PDU plus any trailing advertising bytes, and prior to this fix there was no maximum-length check (only a minimum). An attacker can therefore append extra AD structures or padding after the Solicitation Service Data to make buf->len exceed 17. bt_mesh_scan_cb() is registered directly as the BLE scan callback, so buf is raw, unauthenticated advertising data received over the air. Any device in radio range can send a non-connectable advertisement carrying a crafted mesh Proxy Solicitation to a node that has CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and is currently eligible to be solicited (GATT proxy disabled, On-Demand Private Proxy enabled), with no pairing, bonding, or provisioning. The result is an attacker-controlled stack overwrite — plausibly leading to remote code execution and at minimum a reliable remote denial of service. The fix trims buf->len to the spec-fixed 17 octets (dropping the PDU if fewer remain) before decryption.
Title Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertisement
Weaknesses CWE-121
CWE-787
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-07T08:55:25.103Z

Reserved: 2026-07-15T17:38:10.947Z

Link: CVE-2026-15894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T09:17:05.157

Modified: 2026-10-07T09:17:05.157

Link: CVE-2026-15894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T10:30:14Z

Weaknesses