CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation
Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read.
This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service, which depending on device configuration may or may not require user action.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45813?
CVE-2026-45813 has a high severity rating of 8.8 according to the CVSS 3.1 metrics.
How do I fix CVE-2026-45813?
To fix CVE-2026-45813, apply the patch available from the Apache NimBLE repository.
What impact does CVE-2026-45813 have on Apache NimBLE?
CVE-2026-45813 can lead to a stack buffer overflow or arbitrary out-of-bound read due to improper data validation.
Which operations in Apache NimBLE are affected by CVE-2026-45813?
CVE-2026-45813 affects the 'Add Source' and 'Modify Source' operations in the BASS service.
Is there a risk of exploitation with CVE-2026-45813?
Yes, CVE-2026-45813 is at risk of exploitation through nearby devices that can send crafted PDUs.