Reachable Assertion vulnerability in Apache NimBLE. A...
High severity
Unreviewed
Published
Jul 24, 2026
to the GitHub Advisory Database
•
Updated Jul 24, 2026
Description
Published by the National Vulnerability Database
Jul 24, 2026
Published to the GitHub Advisory Database
Jul 24, 2026
Last updated
Jul 24, 2026
Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.
Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
References