{
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
      },
      "title": "NULL pointer dereference vulnerability in SMP LTK request",
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "CWE-476 NULL Pointer Dereference",
              "lang": "en",
              "cweId": "CWE-476",
              "type": "CWE"
            }
          ]
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "affected": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache NimBLE",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThanOrEqual": "1.9.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ],
      "descriptions": [
        {
          "value": "NULL Pointer Dereference vulnerability in Apache NimBLE in\u00a0LE Long Term Key Request event.\n\nThis requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.",
          "lang": "en",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>NULL Pointer Dereference vulnerability in Apache NimBLE in&nbsp;LE Long Term Key Request event.</p>This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.<br><br><p>This issue affects Apache NimBLE: through 1.9.0.</p><p>Users are recommended to upgrade to version 1.10.0, which fixes the issue.</p>"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/apache/mynewt-nimble/commit/9448c5f495eb55018121b24a9dab5305c9222ea1",
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/psppdk5j8jnq1m4jn96tnfofspgqvzvn",
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "other": {
            "type": "Textual description of severity",
            "content": {
              "text": "low"
            }
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Chongqing Lei <leicq@seu.edu.cn>",
          "type": "reporter"
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "cveId": "CVE-2026-45816",
    "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
    "serial": 1,
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}