CVE-2022-26529: Realtek Bluetooth Mesh Software Development Kit

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.

Affected products

  • Realtek Bluetooth Mesh Software Development Kit: up to and including 4.17-4.17-20220127

Published 2022-08-30. Last modified 2026-06-17.