Out-of-bounds Write Vulnerability in Apache NimBLE BASS Service
CVE-2026-45813

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 July 2026

What is CVE-2026-45813?

The vulnerability in Apache NimBLE BASS service allows for an out-of-bounds write and integer underflow due to improper validation during the parsing of 'Add Source' and 'Modify Source' operation PDUs. Exploitation can lead to stack buffer overflow or unauthorized out-of-bound reads. While the vulnerability requires a prior pairing with a Bluetooth device, its effect could be significant depending on the device configuration. Users should promptly update to version 1.10.0 to mitigate this risk.

Affected Version(s)

Apache NimBLE 0 <= 1.9.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VulnCheck
侯朋朋 <pengpeng@iscas.ac.cn>
.