CVE Explorer
CVE-2026-10774
Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching psa_destroy_key() with CONFIG_BT_MESH_V1d1. That Kconfig symbol was removed when explicit Mesh 1.0.1 support was dropped, so the destroy branch became permanently dead code and the import
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/zephyrproject-rtos/zephyr","defaultStatus":"unaffected","packageName":"zephyr","product":"zephyr","programFiles":["subsys/bluetooth/mesh/subnet.c"],"vendor":"zephyrproject","versions":[{"lessThan":"4.5.0","status":"affected","version":"3.6.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d6088fe8ab01443cfe5b68166beb8c20c655e518e5cc95a38be5500bc1f8d0fe · sha256:a39541268e06c2a6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":2.4,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d6088fe8ab01443cfe5b68166beb8c20c655e518e5cc95a38be5500bc1f8d0fe · sha256:a39541268e06c2a6… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-401","description":"dos","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6088fe8ab01443cfe5b68166beb8c20c655e518e5cc95a38be5500bc1f8d0fe · sha256:a39541268e06c2a6… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"Fix commit","tags":["patch"],"url":"https://github.com/zephyrproject-rtos/zephyr/commit/f573da9f53630082ae95fcfd39fb021fe15f7abd"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6088fe8ab01443cfe5b68166beb8c20c655e518e5cc95a38be5500bc1f8d0fe · sha256:a39541268e06c2a6… · /containers/cna/references/0
{"name":"GHSA-6q7g-798f-76p2","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-6q7g-798f-76p2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6088fe8ab01443cfe5b68166beb8c20c655e518e5cc95a38be5500bc1f8d0fe · sha256:a39541268e06c2a6… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.