What is CVE-2026-11893?
CVE-2026-11893 affects the Zephyr OS Bluetooth HCI driver for Bouffalo Lab BLE controllers (BL60x/BL70x/BL61x). The flaw lies in bt_bflb_send() violating the buffer-ownership contract of bt_hci_driver_api.send(), which can lead to system instability or denial of service. Users should apply patches provided by Zephyr maintainers for affected platforms.
Azərbaycanca: CVE-2026-11893 Bouffalo Lab BLE kontrollerləri (BL60x/BL70x/BL61x) üçün Zephyr OS Bluetooth HCI sürücüsündə aşkarlanıb. Bu boşluq sürücünün bt_hci_driver_api.send() funksiyasında buffer sahibliyi müqaviləsini pozur və potensial system instability və ya denial of service yarada bilər. İstifadəçilər təsirlənmiş platformalar üçün Zephyr tərtibatçıları tərəfindən təqdim edilən yamaqları tətbiq etməlidir.
FAQ2
What component contains the vulnerability described in CVE-2026-11893?
The vulnerability is in the Zephyr OS Bluetooth HCI driver for Bouffalo Lab BLE controllers (BL60x/BL70x/BL61x).
What is the root cause of CVE-2026-11893?
The flaw is caused by bt_bflb_send() violating the buffer-ownership contract of bt_hci_driver_api.send().
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.