Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
{
"cna_assigner": "apache",
"cwe_ids": [
"CWE-120"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45811.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.10.0"
}
],
"cpe": "cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T16:09:37Z"
[
{
"source": "https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41",
"target": {
"file": "nimble/transport/socket/src/ble_hci_socket.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"305133216105487713854478443148965419396",
"191399666240777906614153336694585206296",
"189328387510238465752728574520283989336",
"144523109083615469965045570938412106445"
]
},
"signature_version": "v1",
"signature_type": "Line",
"id": "CVE-2026-45811-345fc104",
"deprecated": false
},
{
"source": "https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41",
"target": {
"function": "ble_hci_sock_rx_msg",
"file": "nimble/transport/socket/src/ble_hci_socket.c"
},
"digest": {
"length": 3300.0,
"function_hash": "330403379549844843441145149534594783226"
},
"signature_version": "v1",
"signature_type": "Function",
"id": "CVE-2026-45811-c4a696df",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45811.json"