A vulnerability was found in zephyrproject-rtos Zephyr up to 4.3.0. It has been rated as critical. Affected is the function
l2cap_chan_le_recv_seg of the file subsys/bluetooth/host/l2cap.c. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2026-5068. The attack can only be initiated within the local network. No exploit exists.