{"id":"CVE-2026-14297","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-14297","summary":"A buffer overflow in the Bluetooth Continuous Glucose\n     Monitoring Service (CGMS) Record Access Control Point (RACP) write handler\n     allows an authenticated BLE peer to overflow…","details":"A buffer overflow in the Bluetooth Continuous Glucose\n     Monitoring Service (CGMS) Record Access Control Point (RACP) write handler\n     allows an authenticated BLE peer to overflow a 20-byte static buffer into\n     adjacent BSS memory. The exploitable impact cannot be predetermined - it\n     is entirely dependent on the linker-assigned BSS layout of the specific\n     firmware build, which may vary.","published":"2026-09-07T09:17:15.430","modified":"2026-09-07T09:17:15.430","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-07T09:17:15.430"}}