Executive brief
Silicon Labs Bluetooth Mesh SDK is used to build mesh networking capabilities into embedded devices. An attacker on a provisioned mesh network can send malformed extended advertisements that cause memory corruption, potentially leading to remote code execution on provisioners that support the extended advertisement feature.
Technical details
The vulnerability is a stack-based buffer overflow triggered by out-of-bounds writes when processing malformed extended advertisements in Bluetooth Mesh SDK 6.1.4 and earlier. The attack requires the attacker to be authenticated as a device already joined to the mesh network, limiting the attack surface to provisioners with extended advertisement support enabled. The malformed messages trigger memory corruption that can be leveraged to achieve remote code execution. Patches are available in Bluetooth Mesh SDK 6.1.5.0 and later (confirmed in GSDK v4.5.0 and v4.5.1).
Affected products
- Silicon Labs Bluetooth Mesh SDK 6.1.4 and earlier
Timeline
- 2026-08-28: disclosed
- 2025-10-08: patched: Fixed in Bluetooth Mesh SDK 6.1.5.0 (GSDK v4.5.0)