CVE-2026-10593Disclosure(zephyrproject / zephyr)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c), the handler writes attacker-controlled QoS fields (interval, framing, phy, sdu, rtn, latency, pd) through the stream->qos pointer with only a stream != NULL guard. stream->qos is NULL for any stream that has been codec-configured via bt_bap_stream_config() but not yet added to a unicast group (it is set only by unicast_group_add_stream()). A malicious or buggy remote ASCS server, to which the local device is connected as a BAP unicast client, can send a GATT notification announcing the ASE has entered the QoS Configured state while the local endpoint is still in the Codec Configured state — a transition the dispatcher explicitly permits — during that window, causing a write through a NULL pointer and a crash (denial of service). The data written is itself remote-controlled. The defect shipped in v4.3.0 and v4.4.0 (and earlier). The fix re-points all BAP QoS storage to the always-valid embedded ep->qos struct, eliminating the NULL dereference.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zephyr

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-06-28); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
zephyr

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-28: 3Mentions · 2026-07-12: 1Technical Details · 2026-06-28: 306-2807-12
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-283
Disclosure3
2026-07-121
General1
Full discourse4 posts
  • LilRhodySpecial@rhody_special
    General

    @agentmail A security nightmare Hypothetical Attack Chain: Email-to-Bluetooth Air-Gap Bypass. Live expolit Has anyone checked ? Doubt it ! Attacker identifies an AI agent's email address and discovers the target facility runs unpatched Zephyr RTOS Bluetooth devices (CVE-2026-10593). 👇

    Post summary

    The post references CVE-2026-10593 but provides no technical details, PoC, exploit, or patch information, and does not report active exploitation.

    10000267
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-10593 The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/blue… https://www.cve.org/CVERecord?id=CVE-2026-10593 ----- Traducción: CVE-2026-10593 El … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-10593, describing a mishandling in Zephyr Bluetooth LE Audio Basic Audio Profile without mentioning any PoC, exploit, or patch.

    0001042
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-10593 The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/blue… https://www.cve.org/CVERecord?id=CVE-2026-10593

    Post summary

    The post announces a Zephyr Bluetooth LE Audio vulnerability involving mishandled ASE state notifications, offering technical details but no PoC, exploit, patch, or evidence of active attacks.

    000101.3K
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-10593 Null Pointer Dereference in Zephyr Bluetooth LE Audio BAP Unicast Client https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-10593

    Post summary

    The post announces a null pointer dereference in Zephyr's Bluetooth LE Audio BAP Unicast Client (CVE-2026-10593) with no exploitation or mitigation details included.

    00010107
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSzephyrprojectzephyr---

Explore more