Buffer Size Calculation Flaw in Apache NimBLE Affects User Applications
CVE-2026-45812
Currently unrated
What is CVE-2026-45812?
The vulnerability involves an incorrect calculation of buffer size in Apache NimBLE during the processing of Legacy Advertising Report HCI events. When multiple HCI advertising reports are bundled into a single event, NimBLE fails to compute the correct offset to the next report. This miscalculation results in the host reading beyond the buffer's end, potentially delivering erroneous data to the applications through a GAP event. It is important to note that this issue is primarily relevant when NimBLE's host is paired with third-party controllers since NimBLE's own controller does not batch multiple reports. Users are advised to upgrade to version 1.10.0 to mitigate this issue.
Affected Version(s)
Apache NimBLE 0 <= 1.9.0