Reachable assertion in Apache NimBLE - CVE-2026-45815
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in ATT Read Multiple Variable Response handler when parsing a specially crafted ATT Read Multiple Variable Response. A remote attacker can send a specially crafted ATT Read Multiple Variable Response to cause a denial of service.
Exploitation requires the device under test to first send an ATT Read Multiple Variable Request.