In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted. | |
| Title | Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements | |
| Weaknesses | CWE-130 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Silabs
Published:
Updated: 2026-08-27T22:13:56.225Z
Reserved: 2026-04-06T15:58:09.629Z
Link: CVE-2026-5706
No data.
Status : Received
Published: 2026-08-28T00:18:07.853
Modified: 2026-08-28T00:18:07.853
Link: CVE-2026-5706
No data.
OpenCVE Enrichment
No data.
Weaknesses