Classic Buffer Overflow Vulnerability in Apache NimBLE
CVE-2026-45811
Currently unrated
What is CVE-2026-45811?
A buffer overflow vulnerability exists in Apache NimBLE's HCI socket transport due to inadequate size checks on received HCI events. This flaw may allow for potential exploitation but primarily requires either a misconfiguration of the pool size or a compromised controller on the HCI socket link. The issue affects all versions of Apache NimBLE up to 1.9.0. To mitigate this risk, users are strongly advised to upgrade to version 1.10.0, which resolves the vulnerability.
Affected Version(s)
Apache NimBLE 0 <= 1.9.0