Incorrect Calculation of Buffer Size in Apache NimBLE - CVE-2026-45812
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect calculation of buffer size in the legacy advertising report hci event handler when processing bundled hci advertising report events containing multiple reports. A remote attacker can send a specially crafted advertising report event to disclose sensitive information.
This only affects deployments where NimBLE host is used with a third-party controller that batches multiple reports into a single event.