CVE-2026-11368 | Zephyr Project up to 4.4.x Bluetooth Host ATT Layer att.c bt_att_released att_chan/reqs use after free
A vulnerability categorized as very critical has been discovered in Zephyr Project Zephyr up to 4.4.x. This impacts the function bt_att_released of the file subsys/bluetooth/host/att.c of the component Bluetooth Host ATT Layer. Executing a manipulation of the argument att_chan/reqs can lead to use after free.
The identification of this vulnerability is CVE-2026-11368. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More