Impact
The vulnerability originates from improper validation of the BASS service’s Add Source and Modify Source PDUs. When an attacker crafts a malformed PDU, the device incorrectly parses the data, leading to a stack buffer overflow or an arbitrary out‑of‑bounds read. This flaw is an instance of integer underflow/wraparound and out‑of‑bounds write and could allow an attacker to execute arbitrary code or otherwise compromise the target device’s integrity.
Affected Systems
The flaw affects the Apache NimBLE library through versions up to and including 1.9.0. The maintainers have released version 1.10.0, which includes the necessary validation fixes, and upgrading to that version resolves the issue.
Risk and Exploitability
The CVSS score of this vulnerability is 8.8, indicating high severity, while the EPSS score is below 1 %, reflecting a relatively low probability of exploitation at present. The flaw is not listed in CISA’s KEV inventory. Exploitation requires a Bluetooth link; the device must be paired with the attacker’s gadget, although whether the pairing step needs user interaction depends on the target’s configuration. Because the intrinsic risk is high but the exploitation window is comparatively narrow, organizations should prioritize patching and consider tightening pairing procedures to mitigate potential attacks.
OpenCVE Enrichment