Sceawere

Vulnerability Detail

CVE-2026-19739UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Bluetooth Controller Memory Leak DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
zephyrproject
Product
zephyr
Attack Type
dos
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits for its instant, so the node can later carry the host notification (llcp_rx_node_retain(), which marks it NODE_RX_TYPE_RETAIN and thereby suppresses the normal recycling in ull.c). The default: arm of llcp_rp_cu_rx() and llcp_lp_cu_rx() — the "invalid PDU, terminate the connection" path — completed the procedure without releasing that retained node. llcp_rr_check_done() then dequeued and freed the procedure context with ctx->node_ref.rx still pointing at the retained node, dropping the last reference to it. A peer device in radio range can reach this without pairing, bonding, or encryption. Against a peripheral, the peer sends a well-formed LL_CONNECTION_UPDATE_IND with an instant a few connection events in the future (the node is retained and the procedure enters RP_CU_STATE_WAIT_INSTANT), then, before the instant is reached, sends any other LL Control PDU such as LL_LENGTH_REQ. ull_cp_rx() routes that PDU into the active remote Connection Update procedure, which takes the invalid-PDU path. The central role is reachable symmetrically after accepting an LL_CONNECTION_PARAM_REQ, and the local-procedure variant is reachable with LL_REJECT_IND. With CONFIG_BT_CTLR_ASSERT_DEBUG enabled (its default), the resulting state violates the invariant asserted in llcp_rr_check_done(), so the two-PDU sequence produces an immediate fatal error in the controller. With those asserts disabled, each occurrence permanently loses one node from the controller's small fixed RX pool (sized from CONFIG_BT_CTLR_RX_BUFFERS, which defaults to 1); repeating the sequence across reconnections exhausts the pool, after which the link-layer receive path operates on a NULL node. The impact is an unauthenticated, remotely triggerable denial of service persisting until reboot; there is no memory-disclosure or memory-corruption consequence, since the leaked node simply becomes unreachable.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-11T18:16:59.170Z",
  "pubdate": "2026-10-11T18:16:59.170Z",
  "executiveSummary": "A memory leak vulnerability exists in the Bluetooth Link Layer controller within the Zephyr RTOS, specifically affecting connection update procedures. The vulnerability is triggered by an improper reference counting mechanism during the handling of specific LL Control PDU sequences.\nThe flaw allows an unauthenticated, remote attacker within radio range to trigger a denial of service (DoS) by causing the depletion of the fixed-size RX buffer pool. Once the RX pool is exhausted, the Link Layer controller fails to process incoming data, effectively dropping the connection and potentially rendering the controller unresponsive until a system reboot.\nThis vulnerability does not facilitate remote code execution or memory disclosure, as the leaked memory simply becomes unreachable. The attack is highly accessible as it requires no pairing, bonding, or encryption, and can be executed against both peripheral and central roles.\nRisk is significant for devices utilizing default configurations where CONFIG_BT_CTLR_RX_BUFFERS is small, as minimal malicious interaction can lead to permanent controller exhaustion.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper handling of `NODE_RX_TYPE_RETAIN` nodes within the `subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c` file. During a Connection Update or Connection Parameter procedure, the controller retains an RX node via `llcp_rx_node_retain()` to later notify the host. This marking suppresses standard node recycling mechanisms in `ull.c`.\nThe failure occurs in the default error-handling path of `llcp_rp_cu_rx()` and `llcp_lp_cu_rx()`. When an invalid PDU is received, the procedure terminates; however, the retained node is not released. Subsequently, `llcp_rr_check_done()` executes, deallocating the procedure context (`ctx`). Because `ctx->node_ref.rx` still points to the retained, unreleased node, the last reference to that node is lost, causing a permanent memory leak.\nAn attacker can exploit this by sending a sequence of two PDUs. First, the attacker sends a well-formed `LL_CONNECTION_UPDATE_IND` with an instant scheduled in the future, forcing the controller into `RP_CU_STATE_WAIT_INSTANT` and triggering the retention of the RX node. Before the instant is reached, the attacker sends a second, invalidating PDU such as `LL_LENGTH_REQ` or `LL_REJECT_IND` (depending on the role). The state machine routes this to the active procedure, which takes the error path and fails to release the retained node.\nIf `CONFIG_BT_CTLR_ASSERT_DEBUG` is enabled, the state mismatch triggers a fatal assertion, causing an immediate crash. If disabled, each successful execution of this sequence permanently leaks a node from the fixed RX pool defined by `CONFIG_BT_CTLR_RX_BUFFERS`. Given that the default configuration often uses a very small pool (e.g., 1), the controller will inevitably reach a state where the receive path operates on a `NULL` node, leading to a persistent DoS state. The vulnerability is effective against both central and peripheral roles, as the state transition logic handles these paths symmetrically."
}