NULL Pointer Dereference Vulnerability in Apache NimBLE Affected by Misbehaving Controller
CVE-2026-45816
Currently unrated
What is CVE-2026-45816?
A NULL Pointer Dereference vulnerability exists in the Apache NimBLE stack, specifically during the LE Long Term Key Request event. This issue occurs only when asserts are disabled and in scenarios with misbehaving controllers, making it a specific and rare occurrence. Users are strongly encouraged to upgrade to version 1.10.0 or later to mitigate this risk.
Affected Version(s)
Apache NimBLE 0 <= 1.9.0