CVE-2026-45811: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Apache Software Foundation Apache NimBLE
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.
AI Analysis
Technical Summary
Apache NimBLE versions through 1.9.0 contain a buffer overflow vulnerability in the HCI socket transport component. The vulnerability arises from a failure to check the size of incoming HCI events against the configured event pool size before copying, allowing an overflow. Exploitation is limited to scenarios where the event pool is misconfigured or the attacker controls the device connected via the HCI socket, not remotely over Bluetooth. The vulnerability is addressed by upgrading to version 1.10.0.
Potential Impact
A buffer overflow could occur if a received HCI event exceeds the configured event pool size, potentially leading to memory corruption. However, exploitation requires local conditions such as a misconfigured event pool or a malicious/compromised controller connected via the HCI socket. Remote exploitation over Bluetooth is not possible. The severity is considered low due to these constraints.
Mitigation Recommendations
Users should upgrade Apache NimBLE to version 1.10.0, which contains the fix for this buffer overflow vulnerability. No other mitigation steps are indicated. Patch status is confirmed by the vendor's recommendation to upgrade to 1.10.0.
CVE-2026-45811: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Apache Software Foundation Apache NimBLE
Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.
CVSS v3.1
Score 7.5high
Affected software
pkg:github/apache/mynewt-nimbleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache NimBLE versions through 1.9.0 contain a buffer overflow vulnerability in the HCI socket transport component. The vulnerability arises from a failure to check the size of incoming HCI events against the configured event pool size before copying, allowing an overflow. Exploitation is limited to scenarios where the event pool is misconfigured or the attacker controls the device connected via the HCI socket, not remotely over Bluetooth. The vulnerability is addressed by upgrading to version 1.10.0.
Potential Impact
A buffer overflow could occur if a received HCI event exceeds the configured event pool size, potentially leading to memory corruption. However, exploitation requires local conditions such as a misconfigured event pool or a malicious/compromised controller connected via the HCI socket. Remote exploitation over Bluetooth is not possible. The severity is considered low due to these constraints.
Mitigation Recommendations
Users should upgrade Apache NimBLE to version 1.10.0, which contains the fix for this buffer overflow vulnerability. No other mitigation steps are indicated. Patch status is confirmed by the vendor's recommendation to upgrade to 1.10.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-05-13T08:48:46.370Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a63602d9c2644c7f8f15024
Added to database: 07/24/2026, 12:53:01 UTC
Last enriched: 07/24/2026, 13:08:33 UTC
Last updated: 07/24/2026, 23:24:42 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.