Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash.
This issue requires broken or bogus Bluetooth controller and thus severity is considered low.
This issue affects Apache NimBLE: through 1.7.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache nimble |
|
| CPEs | cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache nimble |
Fri, 06 Dec 2024 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 26 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 26 Nov 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 26 Nov 2024 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue. | |
| Title | Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler | |
| Weaknesses | CWE-129 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-12-06T10:15:23.820Z
Reserved: 2024-09-23T08:55:51.217Z
Link: CVE-2024-47249
Updated: 2024-11-26T13:09:21.879Z
Status : Analyzed
Published: 2024-11-26T12:15:19.123
Modified: 2025-07-08T14:17:12.870
Link: CVE-2024-47249
No data.
OpenCVE Enrichment
No data.