CVE-2026-19570 | ZephyrProject Zephyr up to 4.4.2 Broadcast Sink bap_broadcast_sink.c base_subgroup_meta_cb out-of-bounds

SecurityVulns

A vulnerability identified as very critical has been detected in ZephyrProject Zephyr up to 4.4.2. Impacted is the function base_subgroup_meta_cb of the file subsys/bluetooth/audio/bap_broadcast_sink.c of the component Broadcast Sink. The manipulation leads to out-of-bounds read.

This vulnerability is traded as CVE-2026-19570. It is possible to initiate the attack remotely. There is no exploit available.

To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More