Description
A buffer overflow in the Bluetooth Continuous Glucose
Monitoring Service (CGMS) Record Access Control Point (RACP) write handler
allows an authenticated BLE peer to overflow a 20-byte static buffer into
adjacent BSS memory. The exploitable impact cannot be predetermined - it
is entirely dependent on the linker-assigned BSS layout of the specific
firmware build, which may vary.
Published: 2026-09-07
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Buffer Overflow
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a classic buffer overflow caused by an unsafe memcpy call in the Continuous Glucose Monitoring Service's Record Access Control Point write handler. An authenticated BLE peer can supply a payload larger than the fixed 20‑byte BSS buffer, causing adjacent memory to be overwritten. The exact consequences are indeterminate because they depend on the layout of the firmware's BSS section, but the overflow could corrupt control data, crash the system, or even allow arbitrary code execution if the overwritten region contains executable pointers or function references.

Affected Systems

This issue affects devices running Nordic Semiconductor ASA's nRF Connect SDK. No specific version ranges are provided, so all current firmware builds that incorporate the affected SDK release are potentially impacted until the overflow is patched or mitigated.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity. Because the attacker must first be authenticated to the device, the attack does not rely on broad public exploits, and the EPSS data is not available, the likelihood of exploitation is uncertain but cannot be dismissed. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread active exploit chains for this specific flaw. Nonetheless, the nature of the overflow and the breadth of memory it can corrupt give attackers a high likelihood of achieving critical impact if they succeed in compromising a related memory area.

Generated by OpenCVE AI on September 7, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest nRF Connect SDK release that includes a fix for the RACP memcpy overflow.
  • Modify the firmware to replace the unsafe memcpy call with a bounds‑checked copy that limits the written data to the 20‑byte buffer.
  • If the RACP functionality is not required by the application, disable or remove it to eliminate the attack surface.

Generated by OpenCVE AI on September 7, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf Connect Sdk
Vendors & Products Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf Connect Sdk

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory. The exploitable impact cannot be predetermined - it is entirely dependent on the linker-assigned BSS layout of the specific firmware build, which may vary.
Title The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nordic Semiconductor Asa Nrf Connect Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: YesWeHack

Published:

Updated: 2026-09-08T15:01:09.643Z

Reserved: 2026-07-01T09:51:25.497Z

Link: CVE-2026-14297

cve-icon Vulnrichment

Updated: 2026-09-08T15:01:06.296Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T09:17:15.430

Modified: 2026-09-09T15:50:19.447

Link: CVE-2026-14297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:38:10Z

Weaknesses