{"id":"CVE-2026-45811","summary":"Apache NimBLE: Buffer overflow in socket HCI transport","details":"Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.\nThe HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.","modified":"2026-08-12T16:09:37.372299Z","published":"2026-07-24T12:09:10.299Z","database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45811.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/24/11"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45811.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/5mkz68y1py0o6zmxtc3l1o8grtrb78m0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45811"},{"type":"FIX","url":"https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/mynewt-nimble","events":[{"introduced":"0"},{"fixed":"a7a156f28954819e158b62dd613008f22f9cf73b"},{"fixed":"dcc4e4f026109eecd507de9479bb5019306a4a41"}],"database_specific":{"cpe":"cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.10.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["nimble_1_9_0_tag","nimble_1_9_0_rc1_tag","nimble_1_8_0_tag","nimble_1_8_0_rc1_tag","nimble_1_7_0_tag","nimble_1_7_0_rc1_tag","nimble_1_6_0_tag","nimble_1_6_0_rc1_tag","nimble_1_5_0_tag","nimble_1_5_0_rc1_tag"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41","target":{"file":"nimble/transport/socket/src/ble_hci_socket.c"},"deprecated":false,"digest":{"line_hashes":["305133216105487713854478443148965419396","191399666240777906614153336694585206296","189328387510238465752728574520283989336","144523109083615469965045570938412106445"],"threshold":0.9},"id":"CVE-2026-45811-345fc104","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"330403379549844843441145149534594783226","length":3300},"id":"CVE-2026-45811-c4a696df","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41","target":{"function":"ble_hci_sock_rx_msg","file":"nimble/transport/socket/src/ble_hci_socket.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45811.json","vanir_signatures_modified":"2026-08-12T16:09:37Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}