https://seclists.org/oss-sec/2026/q3/243: CVE-2026-45816: Apache NimBLE: NULL pointer defence vulnerability in SMP LTK quest
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.9.0
Frequently Asked Questions
1
What is the severity of CVE-2026-45816?
The severity of CVE-2026-45816 is classified as low.
2
What versions of Apache NimBLE are affected by CVE-2026-45816?
Apache NimBLE versions up to and including 1.9.0 are affected by CVE-2026-45816.
3
How do I fix CVE-2026-45816?
To mitigate CVE-2026-45816, it is recommended to disable the feature causing the NULL pointer dereference or update to a fixed version of Apache NimBLE.
4
What causes CVE-2026-45816?
CVE-2026-45816 is caused by a NULL Pointer Dereference in the LE Long Term Key Request event when asserts are disabled and a misbehaving controller is used.
5
Is CVE-2026-45816 exploitable remotely?
CVE-2026-45816 requires a specific misbehaving controller, limiting its exploitability in most scenarios.