Incorrect Calculation of Buffer Size in Apache NimBLE - CVE-2026-45812

 

Incorrect Calculation of Buffer Size in Apache NimBLE - CVE-2026-45812

Published: August 24, 2026


Vulnerability identifier: #VU144748
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45812
CWE-ID: CWE-131
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to incorrect calculation of buffer size in the legacy advertising report hci event handler when processing bundled hci advertising report events containing multiple reports. A remote attacker can send a specially crafted advertising report event to disclose sensitive information.

This only affects deployments where NimBLE host is used with a third-party controller that batches multiple reports into a single event.


Affected software

Apache NimBLE

How to mitigate CVE-2026-45812

Install security update from vendor's website.

Apache NimBLE - update to 1.10.0

External References

Related Security Bulletins