CVE-2026-10658 | zephyrproject-rtos Zephyr up to 4.4.0 iso.c bt_iso_recv len out-of-bounds (GHSA-26g8-rmpf-j6cw)
A vulnerability was found in zephyrproject-rtos Zephyr up to 4.4.0. It has been rated as problematic. The impacted element is the function bt_iso_recv of the file subsys/bluetooth/host/iso.c. This manipulation of the argument len causes out-of-bounds read.
This vulnerability is handled as CVE-2026-10658. The attack can only be done within the local network. There is not any exploit available.