CVE-2026-10685 | ZephyrProject Zephyr up to 4.4.x GATT Client CCC-Write Response gatt.c gatt_write_ccc_rsp use after free
A vulnerability categorized as very critical has been discovered in ZephyrProject Zephyr up to 4.4.x. Affected by this issue is the function gatt_write_ccc_rsp of the file subsys/bluetooth/host/gatt.c of the component GATT Client CCC-Write Response Handler. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-10685. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More