Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
History

Fri, 06 Dec 2024 10:30:00 +0000


Tue, 26 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 14:45:00 +0000

Type Values Removed Values Added
References

Tue, 26 Nov 2024 11:30:00 +0000

Type Values Removed Values Added
Description Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Title Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
Weaknesses CWE-129
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-11-26T11:16:35.626Z

Updated: 2024-12-06T10:15:23.820Z

Reserved: 2024-09-23T08:55:51.217Z

Link: CVE-2024-47249

cve-icon Vulnrichment

Updated: 2024-11-26T13:09:21.879Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-26T12:15:19.123

Modified: 2024-12-06T11:15:08.340

Link: CVE-2024-47249

cve-icon Redhat

No data.