CVE-2026-5068
HIGHCVSS v3.1: 7.6 · EPSS: 0.0001 (3.1 percentile)
Source data as of:
At a glance
- Severity
- HIGH
- CVSS
- 7.6 v3.1 · NVD
- EPSS
- 0.0001 (3.1 percentile) · FIRST.org
- CISA KEV
- No
- Type
- Out-of-bounds Write · NVD CWE
- Attack conditions (CVSS vector)
- No privilegesNo user interaction · Source: NVD Vector
- Published
- 2026-06-09 · Modified: 2026-06-09
- References
- Jump to references (1)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf) and the chosen RX pool has a user_data_size smaller than 2 bytes, the segmentation counter stored in the net_buf user_data area is written out of bounds in l2cap_chan_le_recv_seg (subsys/bluetooth/host/l2cap.c). The observed effects are an AddressSanitizer abort and, without ASan, heap corruption / fatal error.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.