CVE-2026-45811 Details
Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.
A classic buffer overflow vulnerability has been identified in Apache NimBLE versions through 1.9.0. The issue arises in the HCI socket transport, where the system failed to verify whether a received HCI event would fit within the allocated event pool before copying it. This oversight allows for a buffer overflow to occur. The vulnerability's exploitation is considered low severity, as it requires either a misconfigured pool size or a malicious controller on the opposite end of the HCI socket link, rather than over-the-air Bluetooth access.
Users are advised to upgrade to Apache NimBLE version 1.10.0, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/24/11 | CVE | Mailing ListThird Party Advisory |
| https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41 | [email protected] | Patch |
| https://lists.apache.org/thread/5mkz68y1py0o6zmxtc3l1o8grtrb78m0 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache nimble | < 1.10.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | CVE Modified | CVE |
| Jul 24, 2026 | New CVE Received | [email protected] |