
CVE-2026-10651 A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute()… https://www.cve.org/CVERecord?id=CVE-2026-10651
Post summary
This notice describes a vulnerability where a malformed SDP attribute triggers an assertion in Zephyr's SDP parser, providing technical details but no evidence of exploitation or patch status.

