High severity7.5NVD Advisory· Published Jul 24, 2026· Updated Jul 27, 2026
CVE-2026-45816
CVE-2026-45816
Description
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.9.0
Patches
Vulnerability mechanics
References
3- github.com/apache/mynewt-nimble/commit/9448c5f495eb55018121b24a9dab5305c9222ea1nvdPatch
- www.openwall.com/lists/oss-security/2026/07/24/15nvdMailing ListThird Party Advisory
- lists.apache.org/thread/psppdk5j8jnq1m4jn96tnfofspgqvzvnnvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.