A vulnerability was found in Zephyr Project Zephyr up to 4.4.1. It has been rated as problematic. This affects the function bt_bflb_send of the file drivers/bluetooth/hci/hci_bflb.c of the component Bluetooth HCI driver. The manipulation leads to use after free.

This vulnerability is traded as CVE-2026-11893. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.