{"id":"CVE-2026-44634","summary":"Stack buffer overflows in SimpleBLE","details":"SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities in SimpleBLE. There is a stack overflow vulnerability in the dongl backend’s Protocol::simpleble_write function (local, caller-controlled input). A stack overflow vulnerability when processing manufacturer-specific data in BLE advertisements (remote, no pairing or connection required). Lastly, a stack overflow vulnerability when processing service data in BLE advertisements (remote, no pairing or connection required). This issue has been patched in version 0.14.0.","aliases":["GHSA-8h89-q8m2-c8fp"],"modified":"2026-07-15T20:28:03.571611Z","published":"2026-06-09T23:59:31.113Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-121","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44634.json"},"references":[{"type":"WEB","url":"https://github.com/simpleble/simpleble/releases/tag/v0.14.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44634.json"},{"type":"ADVISORY","url":"https://github.com/simpleble/simpleble/security/advisories/GHSA-8h89-q8m2-c8fp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44634"},{"type":"FIX","url":"https://github.com/simpleble/simpleble/commit/1501d59d76a4280268372afb1b157bf6caeacba6"},{"type":"FIX","url":"https://github.com/simpleble/simpleble/pull/466"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simpleble/simpleble","events":[{"introduced":"0"},{"fixed":"1501d59d76a4280268372afb1b157bf6caeacba6"},{"fixed":"5762afd8d83b5d3dc5cd2a33561d746b6de72935"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.14.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v0.12.1","v0.12.0","v0.11.0","v0.10.4","v0.10.3","v0.10.2","v0.10.1","v0.9.1","v0.9.0","v0.8.1","v0.7.3","v0.7.1","v0.7.0","v0.6.1","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.0","v0.1.0","v0.0.2","v0.0.1"],"database_specific":{"vanir_signatures":[{"target":{"file":"simplecble/src/peripheral.cpp"},"deprecated":false,"digest":{"line_hashes":["333688504546538138666434177275355612062","3315279951924140533059467603300984801","126027522690175147924665061679327918835","84687442022352972267782372556837463148","249469434948792608397476383781239270490","227410484410392748241011881074791478302","239288046700959672152987787144769446476","31013372833989615404617677767370828626","82446429642333041878756307513817539302","76266711113211153030133170162721915646","173789218120317605809075380564270918424","122122205643747188739952193979902866961"],"threshold":0.9},"id":"CVE-2026-44634-3ed19c1f","signature_type":"Line","signature_version":"v1","source":"https://github.com/simpleble/simpleble/commit/1501d59d76a4280268372afb1b157bf6caeacba6"},{"id":"CVE-2026-44634-47d87733","signature_type":"Line","signature_version":"v1","source":"https://github.com/simpleble/simpleble/commit/1501d59d76a4280268372afb1b157bf6caeacba6","target":{"file":"simpleble/src/backends/dongl/serial/Protocol.cpp"},"deprecated":false,"digest":{"line_hashes":["125128436277675501249837109718910509102","23697051267741786532226657461757316205","17110709734799827573670947618567413668","318273934195423449465106536995834332944"],"threshold":0.9}},{"id":"CVE-2026-44634-c15450a6","signature_type":"Function","signature_version":"v1","source":"https://github.com/simpleble/simpleble/commit/1501d59d76a4280268372afb1b157bf6caeacba6","target":{"function":"simpleble_peripheral_manufacturer_data_get","file":"simplecble/src/peripheral.cpp"},"deprecated":false,"digest":{"function_hash":"126852759984060285223872062666098078095","length":679}},{"digest":{"function_hash":"21831832004730586364273795724150784442","length":2034},"id":"CVE-2026-44634-d5c088b3","signature_type":"Function","signature_version":"v1","source":"https://github.com/simpleble/simpleble/commit/1501d59d76a4280268372afb1b157bf6caeacba6","target":{"file":"simplecble/src/peripheral.cpp","function":"simpleble_peripheral_services_get"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"41377994412503157635537597706479841629","length":758},"id":"CVE-2026-44634-e561a988","signature_type":"Function","signature_version":"v1","source":"https://github.com/simpleble/simpleble/commit/1501d59d76a4280268372afb1b157bf6caeacba6","target":{"file":"simpleble/src/backends/dongl/serial/Protocol.cpp","function":"Protocol::simpleble_write"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44634.json","vanir_signatures_modified":"2026-07-15T20:28:03Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}