What is CVE-2026-45816?
CVE-2026-45816 is a NULL Pointer Dereference vulnerability in Apache NimBLE during the LE Long Term Key Request event. It requires disabled asserts and a bogus controller, resulting in a low severity impact. Users should update Apache NimBLE beyond version 1.9.0 to mitigate the issue.
Azərbaycanca: CVE-2026-45816 Apache NimBLE-də LE Long Term Key Request hadisəsində NULL Pointer Dereference zəifliyidir. Bu, yalnız assertlər söndürüldükdə və saxta nəzarətçi (controller) istifadə edildikdə baş verə bilər, ona görə də aşağı təsir səviyyəsinə malikdir. Apache NimBLE 1.9.0 və əvvəlki versiyaları təsirlənir, istifadəçilərə təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-476; shared vendor: Apache
FAQ2
What specific conditions are required to exploit CVE-2026-45816?
Exploitation of CVE-2026-45816 requires asserts to be disabled and a bogus controller to be used.
What should users do to protect against CVE-2026-45816?
Users should update Apache NimBLE beyond version 1.9.0 to apply the security fix.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.