Buffer overflow in Apache NimBLE - CVE-2026-45811
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to classic buffer overflow in HCI socket transport when processing a received HCI event. A remote attacker can send a specially crafted HCI event to cause a denial of service.
Exploitation requires either a misconfigured event pool size or a malicious or compromised controller on the other end of the HCI socket link, and does not occur over-the-air Bluetooth access.