Junglewise Threat Intelligence

CVE-2026-45811: Apache NimBLE buffer overflow in HCI socket transport

CVE-2026-45811 · Severity: info · CVSS 3.1 · Published 2026-07-24

Technologies: Apache Software Foundation NimBLE. Vendors: Apache Software Foundation.

Executive brief

Apache NimBLE is an open-source Bluetooth Low Energy stack. A flaw in how it handles communication with Bluetooth hardware controllers could allow a compromised or malicious controller to crash the system by sending oversized data packets. This issue does not allow for remote attacks over-the-air; it requires physical or local access to the hardware interface.

Technical details

A 'Classic Buffer Overflow' (CWE-120) exists in the HCI socket transport component of Apache NimBLE. The vulnerability is caused by a failure to validate that a received Host Controller Interface (HCI) event fits within the configured event pool before performing a copy operation. An attacker with control over the Bluetooth controller (the hardware/firmware on the other end of the HCI socket) can send an oversized event to trigger the overflow. This cannot be exploited over-the-air via Bluetooth. The issue is fixed in version 1.10.0 by dropping HCI events that exceed the BLE_TRANSPORT_EVT_SIZE configuration.

Affected products

  • Apache Software Foundation Apache NimBLE through 1.9.0

Timeline

  • 2026-07-24: advisory: CVE-2026-45811 published by Apache Software Foundation
  • 2026-07-24: patched: Fix committed to mynewt-nimble repository

References

Related threats