CVE-2026-15894 | Zephyr Project up to 4.4.1 Solicitation solicitation.c sol_pdu_decrypt len stack-based overflow
A vulnerability marked as very critical has been reported in Zephyr Project Zephyr up to 4.4.1. Affected by this issue is the function sol_pdu_decrypt of the file subsys/bluetooth/mesh/solicitation.c of the component Solicitation Handler. This manipulation of the argument len causes stack-based buffer overflow.
This vulnerability appears as CVE-2026-15894. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More