CVE-2026-5706
8.9
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H
Summary
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Silicon Labs | BT Mesh SDK | 0 <= 6.1.4, 9.1.0 | affected |
Weaknesses
- CWE-130: CWE-130: Improper Handling of Length Parameter Inconsistency, CWE-787: Out-of-bounds Write
References
- https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/a45Vm000000Et6HIAS?operationContext=S1
- https://github.com/SiliconLabs/gecko_sdk/releases
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.