Description
A buffer overflow in the Bluetooth Continuous Glucose
Monitoring Service (CGMS) Record Access Control Point (RACP) write handler
allows an authenticated BLE peer to overflow a 20-byte static buffer into
adjacent BSS memory. The exploitable impact cannot be predetermined - it
is entirely dependent on the linker-assigned BSS layout of the specific
firmware build, which may vary.
Monitoring Service (CGMS) Record Access Control Point (RACP) write handler
allows an authenticated BLE peer to overflow a 20-byte static buffer into
adjacent BSS memory. The exploitable impact cannot be predetermined - it
is entirely dependent on the linker-assigned BSS layout of the specific
firmware build, which may vary.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory. The exploitable impact cannot be predetermined - it is entirely dependent on the linker-assigned BSS layout of the specific firmware build, which may vary. | |
| Title | The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer. | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: YesWeHack
Published:
Updated: 2026-09-07T08:07:08.746Z
Reserved: 2026-07-01T09:51:25.497Z
Link: CVE-2026-14297
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses