CVE-2026-5706
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.9
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H
- EPSS probability
- 0.27%
- CWE
- CWE-130
- Published
- 2026-08-27
- Last modified
- 2026-08-28
Affected products
- Silicon Labs BT Mesh SDK
Weakness type
Related vulnerabilities
- CVE-2026-71337 — Windows Storage Management Provider Elevation of Privilege Vulnerability
- CVE-2026-71402 — wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length
- CVE-2026-81575 — Missing Sanity Checks for Buffer Lengths
- CVE-2026-58097 — ppp(8): missing length validation in mp_SetEnddisc()
- CVE-2026-58096 — ppp(8): missing length validation in LcpDecodeConfig()
- CVE-2026-14587 — Unathenticated connection can hold Bolt channel open
- CVE-2026-67292 — FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
- CVE-2026-26081 — HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN...