Buffer Overflow in Bluetooth Continuous Glucose Monitoring Service by Nordic Semiconductor
CVE-2026-14297
8.7HIGH
What is CVE-2026-14297?
A buffer overflow vulnerability exists in the Bluetooth Continuous Glucose Monitoring Service (CGMS) specifically in the Record Access Control Point (RACP) write handler. This flaw allows an authenticated Bluetooth Low Energy (BLE) peer to overflow a fixed 20-byte static buffer, impacting adjacent BSS memory. The repercussions of exploiting this vulnerability can vary based on the linker-assigned layout of BSS memory in different firmware builds, making potential outcomes unpredictable. Mitigating this issue is essential for maintaining the integrity and security of health-related data transmission.
Affected Version(s)
nRF Connect SDK 2.2.0 <= 3.3.0
