<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/51036/notice-no-in-119-rev-1-0-1</link><description>Received the IN-119 notice, and it says: 
 All users are recommended to use the latest release of BLE protocol stack software for product development. All BLE protocol stacks from Nordic Semiconductor released after July 2016 are not affected by this</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Fri, 18 Oct 2019 09:49:59 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/51036/notice-no-in-119-rev-1-0-1" /><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/215667?ContentTypeID=1</link><pubDate>Fri, 18 Oct 2019 09:49:59 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:956041fd-314b-4e48-9850-e127e4abb6fc</guid><dc:creator>Joakim Jakobsen</dc:creator><description>&lt;p&gt;The non-compliant BLE protocol stack is the affected versions of the Softdevice.&lt;/p&gt;
&lt;p&gt;All three criterias in my previous answer is required for your device to be affected.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/214931?ContentTypeID=1</link><pubDate>Tue, 15 Oct 2019 00:35:21 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:73ee88e7-79cb-4cb7-a1d0-c0e0ba40e414</guid><dc:creator>m-o</dc:creator><description>&lt;p&gt;I&amp;#39;m sorry.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;I didn&amp;#39;t understand the non-compliant BLE protocol stack.&lt;br /&gt;Is it not applicable when using the SDK?&lt;/p&gt;
&lt;p&gt;Sorry I don&amp;#39;t well know about BLE.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/214853?ContentTypeID=1</link><pubDate>Mon, 14 Oct 2019 13:11:20 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:126e17c2-40ac-4993-9968-8ccc244fbe3a</guid><dc:creator>Joakim Jakobsen</dc:creator><description>&lt;p&gt;Not necessarily.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Please read my previous answer carefully!&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best regards,&amp;nbsp;&lt;br /&gt;Joakim&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/214479?ContentTypeID=1</link><pubDate>Fri, 11 Oct 2019 01:31:23 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:fde715b0-a01d-437e-8072-2c1d64bab9f7</guid><dc:creator>m-o</dc:creator><description>&lt;p&gt;Thank you for your answer.&lt;/p&gt;
&lt;p&gt;Applications is affected that perform service discovery in Central.&lt;/p&gt;
&lt;p&gt;Is my perception correct?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/214417?ContentTypeID=1</link><pubDate>Thu, 10 Oct 2019 14:06:39 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:1d58770b-a29e-4400-bdeb-b93e895dd74a</guid><dc:creator>Joakim Jakobsen</dc:creator><description>&lt;p&gt;Hi.&lt;/p&gt;
&lt;p&gt;As stated in the Notice of Security Vulnerability IN-119: &lt;br /&gt; &lt;em&gt;“The vulnerability requires a non-compliant BLE protocol stack to send invalid, or mal-formed packets in response to request types generated by a GATT Client implementation. This vulnerability is not exposed by qualified implementations of BLE protocol stacks that implement valid behavior.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Affected implementations must have the following criteria:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Use an affected BLE protocol stack&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Use a GATT Client&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Execute a service discovery procedure or a read of a characteristic by UUID which results in one of the following request packet types to be sent to a device implementing a GATT server:&lt;/em&gt;&lt;br /&gt;&lt;em&gt;o READ_BY_TYPE_REQUEST&lt;/em&gt;&lt;br /&gt;&lt;em&gt;o READ_BY_GROUP_TYPE_REQUEST&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Implementations using Central Role are likely to execute a service discovery procedure. If an implementation uses Peripheral Role only, GATT Client is optionally implemented.”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;All three criterias mentioned above is required to be affected, so the application must use an affected BLE softdevice, have a GATT client, and execute a service discovery at the specific time. &lt;br /&gt; If one of the criterias above is not met, then you won’t be affected even if you are using an affected version of the softdevice.&lt;/p&gt;
&lt;p&gt;Best regards,&amp;nbsp;&lt;br /&gt;Joakim&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/214023?ContentTypeID=1</link><pubDate>Wed, 09 Oct 2019 01:52:58 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:97faacd3-53d4-4105-87cd-74301a93ee3b</guid><dc:creator>m-o</dc:creator><description>&lt;p&gt;Is Application definitely affected when using the corresponding soft device?&lt;/p&gt;
&lt;p&gt;The following is not in the source code and I didn&amp;#39;t know if my application was corresponding.&lt;br /&gt;・READ_BY_TYPE_REQUEST&lt;br /&gt;・READ_BY_GROUP_TYPE_REQUEST&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/206529?ContentTypeID=1</link><pubDate>Wed, 28 Aug 2019 08:31:18 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:12414d67-0455-4504-a5c8-6b44902f453c</guid><dc:creator>Joakim Jakobsen</dc:creator><description>&lt;p&gt;Yes, as I said the affected versions is listed in the Notice of Security Vulnerability IN-119.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/206049?ContentTypeID=1</link><pubDate>Mon, 26 Aug 2019 09:12:40 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:0ff2b353-c979-4610-91c1-d7f595c6edea</guid><dc:creator>swibyn</dc:creator><description>&lt;p&gt;Does S130 v2.0.1&amp;nbsp;&lt;span&gt;acceptable?&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/206037?ContentTypeID=1</link><pubDate>Mon, 26 Aug 2019 08:54:19 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e2bb13ea-080c-4b02-b42a-8d7abf6d97dd</guid><dc:creator>swibyn</dc:creator><description>&lt;p&gt;我就想知道到底S130是所有版本都受影响，还是S130就v2.0.0这个版本受影响&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Notice no.: IN-119, rev. 1.0.1</title><link>https://devzone.nordicsemi.com/thread/204507?ContentTypeID=1</link><pubDate>Fri, 16 Aug 2019 12:50:51 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:b735cfcd-1e84-4b09-8398-faeb1b5f2be3</guid><dc:creator>Joakim Jakobsen</dc:creator><description>&lt;p&gt;Hi.&amp;nbsp;&lt;/p&gt;
[quote user=""]Could someone clarify which versions are acceptable, instead of going by date?[/quote]
&lt;p&gt;&amp;nbsp;If you take look at the&amp;nbsp;Informational Notice of Security Vulnerability (IN-119). The affected versions is listed on the top right.&amp;nbsp;&lt;br /&gt;&lt;em&gt;&amp;quot;Product version information: All versions of S110, S120 and S130 S132 v2.0.0&amp;quot;&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
[quote user=""]It looks like SDK 12.2 might be covered, so everything after that should be unaffected?[/quote]
&lt;p&gt;&amp;nbsp;It&amp;#39;s not the SDK itself that is affected by this, but certain versions of the Softdevice (ref. IN-119).&amp;nbsp;&lt;br /&gt;Using SDK v.12.2.0 with Softdevice S132 v.3.0.0 (which is &lt;a href="https://infocenter.nordicsemi.com/topic/com.nordic.infocenter.sdk5.v12.2.0/index.html?cp=5_5_8" rel="noopener noreferrer" target="_blank"&gt;listed as the supported S132 Softdevice&lt;/a&gt;) will not be affected by this.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best regards,&amp;nbsp;&lt;br /&gt;Joakim&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>