{"id":"UBUNTU-CVE-2026-10651","details":"bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf-\u003elen \u003c 3) but then read a fourth byte, the data-element descriptor (type), via net_buf_simple_pull_u8(). Because net_buf_simple_pull_u8() dereferences buf-\u003edata[0] before its only bounds guard (an __ASSERT_NO_MSG that compiles out when CONFIG_ASSERT is disabled, the production default), a record of exactly three bytes (0x09 followed by a 2-byte attribute ID) causes a one-byte read past the end of the logical buffer. The parser is reachable from inbound, remote-controlled data: a Bluetooth BR/EDR peer acting as an SDP server returns discovery-response records that are stored verbatim in the client receive buffer and parsed via the public bt_sdp_get_attr()/bt_sdp_has_attr()/bt_sdp_record_parse() helpers. The over-read is bounded to a single byte that is used only as an internal length selector and is never leaked to the attacker; subsequent length checks then reject the malformed record. Realistic impact is therefore limited to an edge-case denial of service (a fault only if the record ends exactly at a mapped-memory boundary, or a deterministic assert panic when CONFIG_ASSERT=y). Affects Zephyr v4.3.0 and v4.4.0; fixed by adding sizeof(type) to the length check.","modified":"2026-07-15T19:45:16.812926800Z","published":"2026-06-23T01:16:00Z","upstream":["CVE-2026-10651"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-10651"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-10651"},{"type":"REPORT","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p93g-3r68-cj53"}],"affected":[{"package":{"name":"zephyr","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/zephyr?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.2-1","3.1.2-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libzephyr4","binary_version":"3.1.2-1build1"},{"binary_version":"3.1.2-1build1","binary_name":"libzephyr4-krb5"},{"binary_name":"zephyr-clients","binary_version":"3.1.2-1build1"},{"binary_version":"3.1.2-1build1","binary_name":"zephyr-server"},{"binary_version":"3.1.2-1build1","binary_name":"zephyr-server-krb5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-10651.json"}},{"package":{"name":"zephyr","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/zephyr?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.2-1build1","3.1.2-1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"libzephyr4","binary_version":"3.1.2-1build2"},{"binary_name":"libzephyr4-krb5","binary_version":"3.1.2-1build2"},{"binary_version":"3.1.2-1build2","binary_name":"zephyr-clients"},{"binary_version":"3.1.2-1build2","binary_name":"zephyr-server"},{"binary_name":"zephyr-server-krb5","binary_version":"3.1.2-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-10651.json"}},{"package":{"name":"zephyr","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/zephyr?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.2-1build3"],"ecosystem_specific":{"binaries":[{"binary_name":"libzephyr4","binary_version":"3.1.2-1build3"},{"binary_version":"3.1.2-1build3","binary_name":"libzephyr4-krb5"},{"binary_name":"zephyr-clients","binary_version":"3.1.2-1build3"},{"binary_name":"zephyr-server","binary_version":"3.1.2-1build3"},{"binary_version":"3.1.2-1build3","binary_name":"zephyr-server-krb5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-10651.json"}},{"package":{"name":"zephyr","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/zephyr?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.2-1build3"],"ecosystem_specific":{"binaries":[{"binary_name":"libzephyr4","binary_version":"3.1.2-1build3"},{"binary_version":"3.1.2-1build3","binary_name":"libzephyr4-krb5"},{"binary_version":"3.1.2-1build3","binary_name":"zephyr-clients"},{"binary_version":"3.1.2-1build3","binary_name":"zephyr-server"},{"binary_name":"zephyr-server-krb5","binary_version":"3.1.2-1build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-10651.json"}},{"package":{"name":"zephyr","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/zephyr?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.2-1.1","3.1.2-1.1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libzephyr4","binary_version":"3.1.2-1.1build1"},{"binary_name":"libzephyr4-krb5","binary_version":"3.1.2-1.1build1"},{"binary_version":"3.1.2-1.1build1","binary_name":"zephyr-clients"},{"binary_name":"zephyr-server","binary_version":"3.1.2-1.1build1"},{"binary_name":"zephyr-server-krb5","binary_version":"3.1.2-1.1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-10651.json"}},{"package":{"name":"zephyr","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/zephyr?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.2-1.1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libzephyr4","binary_version":"3.1.2-1.1build1"},{"binary_name":"libzephyr4-krb5","binary_version":"3.1.2-1.1build1"},{"binary_name":"zephyr-clients","binary_version":"3.1.2-1.1build1"},{"binary_version":"3.1.2-1.1build1","binary_name":"zephyr-server"},{"binary_name":"zephyr-server-krb5","binary_version":"3.1.2-1.1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-10651.json"}},{"package":{"name":"zephyr","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/zephyr?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.2-1.1build1","3.1.2-4"],"ecosystem_specific":{"binaries":[{"binary_name":"libzephyr4","binary_version":"3.1.2-4"},{"binary_name":"libzephyr4-krb5","binary_version":"3.1.2-4"},{"binary_version":"3.1.2-4","binary_name":"zephyr-clients"},{"binary_name":"zephyr-server","binary_version":"3.1.2-4"},{"binary_name":"zephyr-server-krb5","binary_version":"3.1.2-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-10651.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}