PT-2026-107438 · Zephyr · Zephyr

CVE-2026-15894

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zephyr (affected versions not specified)
Description The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c contains a stack-based buffer overflow. The issue occurs in the sol pdu decrypt() function, where a received Solicitation PDU is copied into a fixed 17-byte stack buffer using net buf simple add mem() without validating the source length. Because the net buf simple add() function only uses assertions for tailroom guards that are removed in production builds, an input length exceeding 17 bytes allows an attacker to overwrite the stack with arbitrary data.
This occurs because the mesh scan callback in subsys/bluetooth/mesh/adv.c calls net buf simple restore() before calling bt mesh sol recv(), causing buf->len to include the entire remaining advertising payload. An attacker can append extra advertising data structures or padding to exceed the buffer limit. Since bt mesh scan cb() processes raw, unauthenticated advertising data, any device within radio range can trigger this by sending a crafted non-connectable advertisement to a node with CONFIG BT MESH OD PRIV PROXY SRV enabled, requiring no pairing, bonding, or provisioning. This can lead to remote code execution or a remote denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, disable the CONFIG BT MESH OD PRIV PROXY SRV configuration to prevent the solicitation handler from processing these requests.

Exploit

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15894
GHSA-X37P-38WQ-CGWJ

Affected Products

Zephyr