Impact
The vulnerability is a memory leak caused by a retained RX node in the Bluetooth Link Layer Control Procedure for Connected Isochronous Stream creation. When a peer sends an unexpected control PDU, the controller drops the procedure but fails to release the retained node, violating an invariant and rendering the node orphaned. This leak can accumulate until the controller’s limited notification pool is exhausted, leading to a fatal assertion and a system reset. The impact is strictly on service availability; no confidentiality or integrity compromise occurs.
Affected Systems
The affected system is the Zephyr Project’s Zephyr RTOS Bluetooth controller, specifically the code that handles Connected Isochronous Stream procedures (CONFIG_BT_CTLR_PERIPHERAL_ISO and CONFIG_BT_CTLR_CENTRAL_ISO). The vulnerability exists regardless of the Zephyr build configuration, but the default build includes debug assertions that trigger a reset on each leak. No specific version or branch information is provided beyond the commit that introduces the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not yet be actively exploited. The attack vector requires only an unpaired, unencrypted ACL link and the ability to send a single additional control PDU, making it feasible for a nearby device to trigger the leak. Because the code path runs in a peripheral or central during ISO creation, an adversary can use this to cause repeated resets or a denial of service without any authentication or user interaction.
OpenCVE Enrichment