Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-45816

CVE-2026-45816: Apache Nimble NULL Pointer Vulnerability

CVE-2026-45816 is a NULL pointer dereference vulnerability in Apache NimBLE affecting LE Long Term Key Request events. This article covers technical details, affected versions through 1.9.0, and mitigation steps.

Updated:

CVE-2026-45816 Overview

CVE-2026-45816 is a NULL pointer dereference vulnerability [CWE-476] in Apache NimBLE, an open-source Bluetooth Low Energy (BLE) stack widely used in embedded and IoT devices. The flaw resides in the handling of the LE Long Term Key Request event within the Security Manager component. When a bogus or misbehaving controller supplies an invalid connection handle and asserts are disabled at build time, the host dereferences a NULL pointer. The issue affects Apache NimBLE versions through 1.9.0 and is fixed in version 1.10.0.

Critical Impact

A remote attacker with a malicious or malfunctioning BLE controller can trigger a NULL pointer dereference, resulting in denial of service on affected NimBLE-based devices.

Affected Products

  • Apache NimBLE versions up to and including 1.9.0
  • Embedded devices and IoT products bundling mynewt-nimble host stack
  • Apache Mynewt deployments using NimBLE with asserts disabled

Discovery Timeline

  • 2026-07-24 - CVE-2026-45816 published to the National Vulnerability Database
  • 2026-07-27 - Last updated in NVD database

Technical Details for CVE-2026-45816

Vulnerability Analysis

The vulnerability exists in the NimBLE host Security Manager (ble_sm.c) code path that processes the LE Long Term Key (LTK) Request event from the controller. When the host receives this event, it looks up the associated connection object using the conn_handle provided by the controller. In vulnerable versions, the lookup result is not validated before the connection pointer is used, leading to a NULL pointer dereference when the handle does not correspond to an active connection.

Exploitation requires a bogus or misbehaving BLE controller and a NimBLE build with asserts disabled. In debug builds, an internal assertion would fire before the dereference occurred. The resulting crash impacts availability of the affected device, which is significant for embedded systems where recovery may require physical intervention.

Root Cause

The root cause is missing validation of the return value from the connection lookup function inside the LE LTK Request handler. The host assumed the controller would only supply valid handles, violating the defensive posture expected across a host-controller trust boundary in the BLE stack.

Attack Vector

The attack vector is network-adjacent through the BLE Host Controller Interface (HCI). An attacker able to influence controller behavior, or a genuinely misbehaving controller, can inject an LE LTK Request event referencing an invalid conn_handle. No authentication or user interaction is required at the host layer to trigger the dereference.

c
// Security patch in nimble/host/src/ble_sm.c
// Fix NULL pointer dereference on invalid conn_handle
    memset(&res, 0, sizeof res);

    ble_hs_lock();

    conn = ble_hs_conn_find_assert(conn_handle);
    if (conn == NULL) {
        ble_hs_unlock();
        return BLE_HS_ENOENT;
    }

    proc = ble_sm_proc_find(conn_handle, BLE_SM_PROC_STATE_NONE, 0, NULL);
    if (proc == NULL) {
        /* The peer is attempting to restore a encrypted connection via the

Source: Apache mynewt-nimble commit 9448c5f

The patch adds an explicit NULL check after ble_hs_conn_find_assert(), releases the host lock, and returns BLE_HS_ENOENT instead of proceeding to dereference the connection pointer.

Detection Methods for CVE-2026-45816

Indicators of Compromise

  • Unexpected reboots or crashes of BLE-enabled devices during pairing or re-encryption attempts
  • Watchdog resets on embedded systems coinciding with incoming BLE connection activity
  • HCI logs showing LE Long Term Key Request events with unknown or stale connection handles

Detection Strategies

  • Enable NimBLE assertions during development and QA builds to surface invalid conn_handle values before they reach production
  • Monitor device crash telemetry for stack traces referencing ble_sm_ltk_req_rx or related Security Manager functions
  • Inspect BLE controller firmware behavior for spurious HCI events sent to the host stack

Monitoring Recommendations

  • Aggregate device crash reports and correlate with BLE pairing activity using centralized log ingestion
  • Track firmware versions across fleets to identify devices still running NimBLE 1.9.0 or earlier
  • Alert on repeated BLE-related crash patterns that may indicate an attacker probing for the flaw

How to Mitigate CVE-2026-45816

Immediate Actions Required

  • Upgrade Apache NimBLE to version 1.10.0 or later, which contains the validated conn_handle lookup fix
  • Rebuild and redistribute firmware for embedded and IoT products that bundle the NimBLE host stack
  • Inventory all devices using mynewt-nimble and prioritize patch deployment for network-exposed BLE endpoints

Patch Information

The fix is available in Apache NimBLE 1.10.0 via commit 9448c5f495eb55018121b24a9dab5305c9222ea1. The patch adds a NULL check for the connection pointer returned by ble_hs_conn_find_assert() in nimble/host/src/ble_sm.c. Refer to the Apache mailing list advisory and the Openwall OSS Security notice for additional context.

Workarounds

  • Enable NimBLE asserts in production builds where feasible, which causes the assert to fire before the NULL dereference occurs
  • Restrict BLE pairing to trusted controllers and validate controller firmware integrity where the host-controller boundary is under vendor control
  • Disable BLE functionality on devices where the feature is not required until firmware updates are applied
bash
# Verify installed NimBLE version and update source tree
git -C mynewt-nimble describe --tags
git -C mynewt-nimble fetch --tags
git -C mynewt-nimble checkout nimble_1_10_0_tag
# Rebuild firmware with the patched stack
newt build <target>
newt create-image <target> 1.10.0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.