CVE-2026-5068: bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data

Published Jun 9, 2026
·
Updated

A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chanops.allocbuf) and the chosen RX pool has a userdatasize smaller than 2 bytes, the segmentation counter stored in the netbuf userdata area is written out of bounds in l2capchanlerecvseg (subsys/bluetooth/host/l2cap.c). The observed effects are an AddressSanitizer abort and, without ASan, heap corruption / fatal error.

Affected Software

2 affected components
Zephyr Project Zephyr
zephyrproject zephyr<=4.4.0

Event History

Jun 9, 2026
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-5068?

CVE-2026-5068 has a severity score of 7.6, categorized as high.

2

How does CVE-2026-5068 affect the Zephyr Project?

CVE-2026-5068 allows a remote unauthenticated BLE peer to cause a 2-byte out-of-bounds write in the Bluetooth host.

3

What conditions must be met for CVE-2026-5068 to be exploited?

To exploit CVE-2026-5068, segmentation must be enabled in the Bluetooth host, and the RX pool's user_data_size needs to be smaller than 2 bytes.

4

What is the impact of CVE-2026-5068 on system security?

CVE-2026-5068 can lead to a high impact denial of service due to the out-of-bounds write vulnerability.

5

How can I mitigate the risks associated with CVE-2026-5068?

To mitigate CVE-2026-5068, ensure that the user_data_size is appropriately configured to avoid out-of-bounds writes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203