boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-10593MEDIUM
zephyrproject zephyr — Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   N  U  N  N  H    6.5   .0028   20.8     —
AFFECTED
  Product  Versions  Fixed
  zephyr   4.3.0 –   —
TIMELINE
  Jun 1   Reserved by zephyr
  Jun 28  EXPLOIT PUBLISHED — CVE-2026-10593 (zephyrproject zephyr). Public exploit reference added.
  Jun 28  Published (CNA: zephyr)
CWE-476 · CNA: zephyr · CVSS v3.1 · 2 references · NVD status: Modified

Description

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c), the handler writes attacker-controlled QoS fields (interval, framing, phy, sdu, rtn, latency, pd) through the stream->qos pointer with only a stream != NULL guard. stream->qos is NULL for any stream that has been codec-configured via bt_bap_stream_config() but not yet added to a unicast group (it is set only by unicast_group_add_stream()). A malicious or buggy remote ASCS server, to which the local device is connected as a BAP unicast client, can send a GATT notification announcing the ASE has entered the QoS Configured state while the local endpoint is still in the Codec Configured state — a transition the dispatcher explicitly permits — during that window, causing a write through a NULL pointer and a crash (denial of service). The data written is itself remote-controlled. The defect shipped in v4.3.0 and v4.4.0 (and earlier). The fix re-points all BAP QoS storage to the always-valid embedded ep->qos struct, eliminating the NULL dereference.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 1, 2026ReservedReserved by zephyr
June 28, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-10593 (zephyrproject zephyr). Public exploit reference added.
June 28, 2026PublishedPublished (CNA: zephyr)

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
zephyrprojectzephyr4.3.0

Weaknesses

CWE-476

References (2)

Related

Authoritative record: CVE-2026-10593 at cve.org

Vendors: zephyrproject

Weaknesses: CWE-476

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-10593 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.