Executive brief
Apache NimBLE, a Bluetooth Low Energy stack, contains a flaw in how it processes certain wireless advertising reports. When used with specific third-party Bluetooth hardware that bundles multiple reports together, the software may misinterpret the data, leading to the processing of incorrect or 'bogus' information. This could potentially cause minor application errors or instability when receiving Bluetooth signals from nearby devices.
Technical details
An incorrect buffer size calculation exists in Apache NimBLE's host component within the `ble_hs_hci_evt_le_adv_rpt` function. When a single HCI advertising report event contains multiple bundled reports, the code miscalculates the offset to the next report by using the size of a pointer instead of the size of the underlying structure. This results in an out-of-bounds read, causing the host to deliver a Generic Access Profile (GAP) event with invalid data to the application. The vulnerability is primarily reachable when NimBLE is paired with a third-party Bluetooth controller that batches reports, as NimBLE's own controller does not exhibit this behavior. The issue is fixed in version 1.10.0.
Affected products
- Apache Software Foundation NimBLE through 1.9.0
Timeline
- 2026-07-24: advisory: Vulnerability disclosed by Apache
- 2026-07-24: patched: Fixed in version 1.10.0