PT-2026-64280 · Apache · Apache Nimble
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NimBLE versions prior to 1.10.0
Description
An incorrect calculation of buffer size occurs when processing Legacy Advertising Report HCI events. When a single HCI advertising report event bundles multiple reports, the software miscalculates the offset to the next report. This can lead the host to read past the end of the buffer and deliver a GAP (Generic Access Profile) event containing bogus data to the application. This issue specifically manifests when the host is paired with a third-party controller that batches multiple reports into one event.
Recommendations
Upgrade to version 1.10.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nimble