PT-2026-64280 · Apache · Apache Nimble

·

CVE-2026-45812

·

Published

2026-07-24

·

Updated

2026-07-27

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache NimBLE versions prior to 1.10.0
Description An incorrect calculation of buffer size occurs when processing Legacy Advertising Report HCI events. When a single HCI advertising report event bundles multiple reports, the software miscalculates the offset to the next report. This can lead the host to read past the end of the buffer and deliver a GAP (Generic Access Profile) event containing bogus data to the application. This issue specifically manifests when the host is paired with a third-party controller that batches multiple reports into one event.
Recommendations Upgrade to version 1.10.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45812

Affected Products

Apache Nimble