CVE-2026-45813
Apache · NimBLE
The Apache NimBLE BASS service is affected by an out-of-bounds write and integer underflow vulnerability, which could lead to memory corruption.
Executive summary
A memory corruption vulnerability in the Apache NimBLE BASS service poses a high risk of service disruption or arbitrary code execution.
Vulnerability
This vulnerability involves an out-of-bounds write (CWE-787) and an integer underflow (CWE-191) within the BASS service. These memory safety issues can be triggered by unauthenticated attackers, potentially leading to system crashes or arbitrary code execution.
Business impact
Successful exploitation can result in complete system instability or the execution of malicious code, severely impacting the availability and security of devices running the affected NimBLE version. Given the CVSS score of 8.8, this vulnerability is critical for embedded environments and IoT deployments relying on the NimBLE stack.
Remediation
Immediate Action: Apply the vendor security updates provided by the Apache NimBLE project.
Proactive Monitoring: Monitor system logs for unexpected reboots, service crashes, or anomalous behavior in the Bluetooth service stack.
Compensating Controls: Isolate devices running the vulnerable BASS service from untrusted networks to reduce the attack surface.
Exploitation status
Public Exploit Available: No confirmed public exploit exists in our curated sources.
Analyst recommendation
Users and maintainers of Apache NimBLE should prioritize applying the provided security patches. Given the potential for system-level impact, testing and deployment of these updates should be conducted as soon as possible.