Impact
The Zephyr Bluetooth LE controller exhibits a retained receive node leak during the PHY Update procedure. When a peer sends a valid LL_PHY_UPDATE_IND, the controller keeps the receive node for future host notification. The code path for invalid control PDUs fails to release this node before freeing the procedure context, leaving the node orphaned. In configurations where assertions are enabled, the bug triggers an assertion failure that can crash the controller; when assertions are disabled the bug silently leaks nodes. Repeated execution of the crafted PDU sequence can exhaust the controller’s small receive pool, rendering Bluetooth inoperable until a reboot. The flaw does not trigger memory corruption or information disclosure, but it enables a denial‑of‑service attack that can be carried out over radio range without pairing or encryption.
Affected Systems
The vulnerability affects the Zephyr RTOS Bluetooth Low‑Energy controller, specifically releases version 3.4.0 through 3.7.x. The issue originates in the LLCP modules that handle PHY Update, Connection Update, and CIS‑create procedures. Users running these Zephyr releases with the default configuration (CONFIG_BT_ASSERT and CONFIG_BT_CTLR_ASSERT_DEBUG enabled) are potentially exposed.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is medium severity. No EPSS data is available, and the flaw is not currently listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can deterministically trigger the bug by sending a crafted sequence of LE control PDUs from within radio range, without requiring pairing or encryption. If assertions are enabled the attacker can cause the controller to crash immediately; otherwise the attacker can leak a single receive node per attack, eventually exhausting the limited receive pool and causing a service outage. No publicly available exploit is known at this time, but the deterministic nature of the attack vector and lack of defensive checks make it a plausible threat.
OpenCVE Enrichment