PT-2026-108756 · Zephyrproject · Zephyr

CVE-2026-19570

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The LE Audio Broadcast Sink in subsys/bluetooth/audio/bap broadcast sink.c copies subgroup metadata from a received Basic Audio Announcement (BASE) into the static Broadcast Audio Scan Service parameter structure mod src param without any bounds check. In base subgroup meta cb() the destination element was selected as mod src param.subgroups[mod src param.num subgroups] with no test against ARRAY SIZE(mod src param.subgroups) (sized by CONFIG BT BAP BASS MAX SUBGROUPS, default 1), and the metadata was copied with memcpy() using the raw on-air length returned by bt bap base get subgroup codec meta() into a metadata array sized by CONFIG BT AUDIO CODEC CFG MAX METADATA SIZE (default 4). The BASE validator bt bap base get base from ad() only checks structural consistency and permits up to ~24 subgroups and metadata LTVs of ~240 octets.
The defect is reached from the periodic advertising receive callback: pa recv() → bt data parse() → pa decode base() → update recv state base() → bt bap base foreach subgroup() → base subgroup meta cb(). Every broadcast sink registers a scan-delegator receive state at creation (bt bap broadcast sink create() calls broadcast sink add src()), and CONFIG BT BAP BROADCAST SINK depends on CONFIG BT BAP SCAN DELEGATOR, so the path is active in every broadcast-sink build once the device is periodic-advertising-synced. An attacker in radio range who operates a broadcast source the device syncs to — or who impersonates the advertiser address and SID of one already in use, periodic advertising data being unauthenticated — can change the BASE at will; each new BASE is re-parsed.
A crafted BASE therefore writes attacker-chosen bytes past the end of a fixed static object in .bss: up to roughly 236 bytes for an oversized metadata LTV, plus whole struct bt bap bass subgroup records for each subgroup beyond CONFIG BT BAP BASS MAX SUBGROUPS. This is memory corruption of adjacent Bluetooth-audio state reachable with no pairing, bonding or GATT connection, with a potential for remote code execution in the Bluetooth RX thread; in addition, the unvalidated metadata len is forwarded to bt bap scan delegator mod src(), which neither clamps it nor rejects it, leading to a further copy into the receive state and to out-of-bounds memory being disclosed in the BASS receive-state notification sent to a connected Broadcast Assistant.
The fix rejects a BASE carrying more subgroups than the receive state can hold (discarding the update entirely) and omits metadata that does not fit rather than copying it, and additionally honours the previously-ignored error return of the subgroup decode pass.

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19570

Affected Products

Zephyr