What is CVE-2026-10675?
CVE-2026-10675 exists in Zephyr's Bluetooth Mesh PB-ADV provisioning bearer. The vulnerability arises from `prov_msg_recv()` unconditionally rescheduling the watchdog timer before the FCS and ADV_LINK_INVALID checks, potentially causing a device to become unresponsive after a failed provisioning attempt. Users should apply the security patch provided by the Zephyr project.
Azərbaycanca: CVE-2026-10675 Zephyr real-time əməliyyat sisteminin Bluetooth Mesh PB-ADV təchizat daşıyıcısında aşkarlanıb. Zəiflik `prov_msg_recv()` funksiyasında watchdog taymerinin FCS və keçərlilik yoxlamalarından əvvəl şərtsiz yenidən başladılması səbəbindən uğursuz təchizat cəhdindən sonra cihazın cavabsız qalmasına yol aça bilər. İstifadəçilərə Zephyr layihəsinin təqdim etdiyi təhlükəsizlik yamasını tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: Zephyr
FAQ2
In which component of Zephyr was CVE-2026-10675 discovered?
In the Bluetooth Mesh PB-ADV provisioning bearer.
What issue can this vulnerability cause on a device after a failed provisioning attempt?
The device could become unresponsive.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.