Unrated severityNVD Advisory· Published Jul 24, 2026· Updated Jul 24, 2026
Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request
CVE-2026-45816
Description
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Affected products
2- Range: <=1.9.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.