Out-of-bounds write in Apache NimBLE - CVE-2026-45813
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service or disclose sensitive information.
The vulnerability exists due to improper input validation in the BASS service add/modify source operation parser when parsing BASS service "Add Source" and "Modify Source" operation PDUs over a Bluetooth connection. A remote user can send a specially crafted PDU to cause a denial of service or disclose sensitive information.
Pairing is required prior to accessing the BASS service, and depending on device configuration this may require user interaction.