https://seclists.org/oss-sec/2026/q3/240: CVE-2026-45812: Apache NimBLE: OOB ad via sizeof(pointer) in Legacy Advertising port Handler
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.9.0
Frequently Asked Questions
1
What is the severity of CVE-2026-45812?
The severity of CVE-2026-45812 is classified as low.
2
Which versions are affected by CVE-2026-45812?
CVE-2026-45812 affects Apache NimBLE versions up to and including 1.9.0.
3
What is the nature of the vulnerability in CVE-2026-45812?
CVE-2026-45812 is due to an incorrect calculation of buffer size when processing Legacy Advertising Report HCI events in Apache NimBLE.
4
How do I fix CVE-2026-45812?
To fix CVE-2026-45812, upgrade Apache NimBLE to a version beyond 1.9.0.
5
What potential impact does CVE-2026-45812 pose?
CVE-2026-45812 could potentially lead to out-of-bounds access due to buffer miscalculation in the advertising report processing.