PT-2026-107438 · Zephyr · Zephyr
CVE-2026-15894
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr (affected versions not specified)
Description
The Bluetooth Mesh On-Demand Private Proxy solicitation handler in
subsys/bluetooth/mesh/solicitation.c contains a stack-based buffer overflow. The issue occurs in the sol pdu decrypt() function, where a received Solicitation PDU is copied into a fixed 17-byte stack buffer using net buf simple add mem() without validating the source length. Because the net buf simple add() function only uses assertions for tailroom guards that are removed in production builds, an input length exceeding 17 bytes allows an attacker to overwrite the stack with arbitrary data.This occurs because the mesh scan callback in
subsys/bluetooth/mesh/adv.c calls net buf simple restore() before calling bt mesh sol recv(), causing buf->len to include the entire remaining advertising payload. An attacker can append extra advertising data structures or padding to exceed the buffer limit. Since bt mesh scan cb() processes raw, unauthenticated advertising data, any device within radio range can trigger this by sending a crafted non-connectable advertisement to a node with CONFIG BT MESH OD PRIV PROXY SRV enabled, requiring no pairing, bonding, or provisioning. This can lead to remote code execution or a remote denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, disable the
CONFIG BT MESH OD PRIV PROXY SRV configuration to prevent the solicitation handler from processing these requests.Exploit
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zephyr