What is CVE-2026-10774?
CVE-2026-10774 is a PSA Crypto key slot leak in Zephyr's Bluetooth Mesh subnet key management. Every subnet-key teardown leaks one key slot due to missing cleanup in subnet_keys_destroy(), potentially exhausting key storage under default configurations. Users should apply the vendor patch to prevent resource starvation.
Azərbaycanca: CVE-2026-10774 Zephyr OS-un Bluetooth Mesh alt şəbəkə açar idarəetməsində PSA Crypto key slot sızmasıdır. Hər alt şəbəkə açarı söküldükdə bir PSA Crypto key slot-u sərbəst buraxılmır, nəticədə yaddaş resursları tükənə bilər. Defolt olaraq aktiv olan bu funksionallıq sistemin dayanıqlığını itirməsinə səbəb ola bilər, istifadəçilərə yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which component of Zephyr OS was the CVE-2026-10774 vulnerability found?
CVE-2026-10774 was found in the Bluetooth Mesh subnet key management of Zephyr OS.
What is the root cause of the CVE-2026-10774 vulnerability?
The root cause of CVE-2026-10774 is that PSA Crypto key slots are not released when subnet keys are torn down.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.