Description
The Link Layer Control Procedure (LLCP) implementation of the Zephyr software Bluetooth LE Controller retains the receive node that carried an accepted LL_PHY_UPDATE_IND so that it can later be reused for the host notification when the update instant is reached (llcp_rx_node_retain() in subsys/bluetooth/controller/ll_sw/ull_llcp.c, and the node is deliberately not recycled while marked NODE_RX_TYPE_RETAIN). The invalid-PDU arms of llcp_lp_pu_rx() and llcp_rp_pu_rx() in subsys/bluetooth/controller/ll_sw/ull_llcp_phy.c completed the procedure via llcp_lr_complete() / llcp_rr_complete() without first releasing that retained node, so the procedure context — the only remaining reference to the node — was freed while the node was still held out of the receive pool.

A peer device on an established LE connection can drive this deterministically and without pairing or encryption. Against a peripheral it sends LL_PHY_REQ, receives LL_PHY_RSP, sends a valid LL_PHY_UPDATE_IND with an instant a few connection events in the future (so the node becomes retained), and then, before the instant is reached, sends any other LL Control PDU such as LL_LENGTH_REQ; ull_cp_rx() routes it to the active remote PHY Update procedure, which takes the invalid-PDU path. The mirror case applies to a locally initiated PHY Update followed by an LL_REJECT_IND.

In the default configuration (CONFIG_BT_ASSERT and CONFIG_BT_CTLR_ASSERT_DEBUG both default y) the violated invariant in llcp_lr_check_done() / llcp_rr_check_done() triggers a controller assertion, ending in k_oops() (or k_panic()) — a single crafted PDU sequence from radio range faults the device. With those assertions compiled out, each attempt silently leaks one receive PDU node and its memq link; because the controller receive pool is small (PDU_RX_CNT, driven by CONFIG_BT_CTLR_RX_BUFFERS, which defaults to 1) and each attempt costs the attacker only a reconnect, a few repetitions exhaust the pool and leave Bluetooth inoperable until reboot. On releases v3.4.0 through v3.7.x the assertion is never reached, whatever the configuration, so every attempt leaks silently.

The impact is limited to availability: the orphaned node leaves no dangling pointer that is later dereferenced and is never delivered to the host, so there is no memory corruption or information disclosure. The same pull request applies the identical release to the Connection Update and CIS-create procedures, whose invalid-PDU arms had the same omission.
Published: 2026-10-11
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Availability
Action: Patch Immediately
AI Analysis

Impact

The Zephyr Bluetooth LE controller exhibits a retained receive node leak during the PHY Update procedure. When a peer sends a valid LL_PHY_UPDATE_IND, the controller keeps the receive node for future host notification. The code path for invalid control PDUs fails to release this node before freeing the procedure context, leaving the node orphaned. In configurations where assertions are enabled, the bug triggers an assertion failure that can crash the controller; when assertions are disabled the bug silently leaks nodes. Repeated execution of the crafted PDU sequence can exhaust the controller’s small receive pool, rendering Bluetooth inoperable until a reboot. The flaw does not trigger memory corruption or information disclosure, but it enables a denial‑of‑service attack that can be carried out over radio range without pairing or encryption.

Affected Systems

The vulnerability affects the Zephyr RTOS Bluetooth Low‑Energy controller, specifically releases version 3.4.0 through 3.7.x. The issue originates in the LLCP modules that handle PHY Update, Connection Update, and CIS‑create procedures. Users running these Zephyr releases with the default configuration (CONFIG_BT_ASSERT and CONFIG_BT_CTLR_ASSERT_DEBUG enabled) are potentially exposed.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is medium severity. No EPSS data is available, and the flaw is not currently listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can deterministically trigger the bug by sending a crafted sequence of LE control PDUs from within radio range, without requiring pairing or encryption. If assertions are enabled the attacker can cause the controller to crash immediately; otherwise the attacker can leak a single receive node per attack, eventually exhausting the limited receive pool and causing a service outage. No publicly available exploit is known at this time, but the deterministic nature of the attack vector and lack of defensive checks make it a plausible threat.

Generated by OpenCVE AI on October 11, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zephyr to a release that includes the patch referenced in https://github.com/zephyrproject-rtos/zephyr/commit/06bf10e3de16b57b864f969330188b59f7d69a63 or apply the Fix commit to the controller source code.
  • As a temporary measure, increase the controller receive buffer count by setting CONFIG_BT_CTLR_RX_BUFFERS to a higher value to mitigate exhaustion of the pool.
  • If disabling assertions is acceptable in your environment, set CONFIG_BT_ASSERT=n and CONFIG_BT_CTLR_ASSERT_DEBUG=n to avoid crashes, but note that silent leaks will still occur and may lead to eventual denial of service.

Generated by OpenCVE AI on October 11, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 11 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description The Link Layer Control Procedure (LLCP) implementation of the Zephyr software Bluetooth LE Controller retains the receive node that carried an accepted LL_PHY_UPDATE_IND so that it can later be reused for the host notification when the update instant is reached (llcp_rx_node_retain() in subsys/bluetooth/controller/ll_sw/ull_llcp.c, and the node is deliberately not recycled while marked NODE_RX_TYPE_RETAIN). The invalid-PDU arms of llcp_lp_pu_rx() and llcp_rp_pu_rx() in subsys/bluetooth/controller/ll_sw/ull_llcp_phy.c completed the procedure via llcp_lr_complete() / llcp_rr_complete() without first releasing that retained node, so the procedure context — the only remaining reference to the node — was freed while the node was still held out of the receive pool. A peer device on an established LE connection can drive this deterministically and without pairing or encryption. Against a peripheral it sends LL_PHY_REQ, receives LL_PHY_RSP, sends a valid LL_PHY_UPDATE_IND with an instant a few connection events in the future (so the node becomes retained), and then, before the instant is reached, sends any other LL Control PDU such as LL_LENGTH_REQ; ull_cp_rx() routes it to the active remote PHY Update procedure, which takes the invalid-PDU path. The mirror case applies to a locally initiated PHY Update followed by an LL_REJECT_IND. In the default configuration (CONFIG_BT_ASSERT and CONFIG_BT_CTLR_ASSERT_DEBUG both default y) the violated invariant in llcp_lr_check_done() / llcp_rr_check_done() triggers a controller assertion, ending in k_oops() (or k_panic()) — a single crafted PDU sequence from radio range faults the device. With those assertions compiled out, each attempt silently leaks one receive PDU node and its memq link; because the controller receive pool is small (PDU_RX_CNT, driven by CONFIG_BT_CTLR_RX_BUFFERS, which defaults to 1) and each attempt costs the attacker only a reconnect, a few repetitions exhaust the pool and leave Bluetooth inoperable until reboot. On releases v3.4.0 through v3.7.x the assertion is never reached, whatever the configuration, so every attempt leaks silently. The impact is limited to availability: the orphaned node leaves no dangling pointer that is later dereferenced and is never delivered to the host, so there is no memory corruption or information disclosure. The same pull request applies the identical release to the Connection Update and CIS-create procedures, whose invalid-PDU arms had the same omission.
Title Bluetooth LE Controller: retained RX node leak and reachable assertion in the PHY Update procedure
Weaknesses CWE-401
CWE-459
CWE-617
CWE-772
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-11T17:15:08.080Z

Reserved: 2026-08-13T13:46:34.001Z

Link: CVE-2026-19740

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T18:16:59.290

Modified: 2026-10-11T18:16:59.290

Link: CVE-2026-19740

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T18:30:19Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-459

    Incomplete Cleanup

  • CWE-617

    Reachable Assertion

  • CWE-772

    Missing Release of Resource after Effective Lifetime