What is CVE-2026-45813?
A critical vulnerability in Apache NimBLE's BASS service arises from improper validation of "Add Source" and "Modify Source" operation PDUs. A remote attacker could trigger a stack buffer overflow or arbitrary out-of-bound read, potentially leading to device compromise. Immediate update from Apache is required.
Azərbaycanca: Bu kritik zəiflik Apache NimBLE-in BASS xidmətində "Add Source" və "Modify Source" əməliyyat PDU-larının düzgün yoxlanılmaması səbəbindən yaranır. Uzaqdan hücumçu stack bufer daşmasına (overflow) və ya özbaşına sərhəddən kənar oxumağa (out-of-bound read) səbəb ola bilər ki, bu da cihazın ələ keçirilməsi ilə nəticələnə bilər. Dərhal Apache tərəfindən təqdim olunan yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Apache
FAQ2
In which service of Apache NimBLE was CVE-2026-45813 discovered?
This critical vulnerability was discovered in the BASS service of Apache NimBLE.
How can a remote attacker exploit CVE-2026-45813?
A remote attacker could exploit improper validation of "Add Source" and "Modify Source" operation PDUs to trigger a stack buffer overflow or arbitrary out-of-bound read.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.