CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45816?
The severity of CVE-2026-45816 is rated high with a CVSS score of 7.5.
How do I fix CVE-2026-45816?
To fix CVE-2026-45816, ensure to update Apache NimBLE to the latest version beyond 1.9.0.
What type of vulnerability is CVE-2026-45816?
CVE-2026-45816 is a NULL Pointer Dereference vulnerability occurring during the LE Long Term Key Request.
What conditions are required for CVE-2026-45816 to be exploited?
CVE-2026-45816 can be exploited when asserts are disabled and when a bogus or misbehaving controller is present.
Which versions of Apache NimBLE are affected by CVE-2026-45816?
CVE-2026-45816 affects Apache NimBLE versions up to and including 1.9.0.