GHSA-f29w-mc54-fh2cHigh

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of...

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.

🔗 References (4)