Impact
A flaw in the Zephyr Bluetooth controller improperly retains a receive node when an unexpected LL Control PDU is received during a Connection Update procedure. The retained node remains marked as NODE_RX_TYPE_RETAIN and is never recycled, leading to a loss of a pool entry each time the sequence is triggered. The resulting denial of service manifests as a fatal error when asserts are enabled, or a permanent exhaustion of the fixed RX buffer pool when they are disabled. Attackers can trigger this condition by sending a carefully timed LL_CONNECTION_UPDATE_IND followed by any other LL Control PDU without requiring pairing, bonding, or encryption, causing the controller to crash or enter an invalid state until reboot.
Affected Systems
The vulnerability affects the Bluetooth Link Layer implementation in the Zephyr project’s Zephyr RTOS. No specific version range is published, but the issue resides in the source path subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c and can impact any Zephyr build that includes the current Bluetooth controller code until the patch committed on 7b600129faaba8bb26dd5cb3e8f17ed1cb41ea7f is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. Exploitation requires only local wireless proximity and does not rely on authentication or encryption, meaning any nearby device can trigger the denial of service. While the EPSS score is not available, the lack of a CISA KEV listing suggests a lower current exploitation likelihood, yet the UNauthenticated, remote trigger remains a serious operational risk.
OpenCVE Enrichment