CVE-2024-24746

Name
CVE-2024-24746
Description
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@apache.org https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078
security@apache.org https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594
security@apache.org http://www.openwall.com/lists/oss-security/2024/04/05/2

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:* nimble >= None < 1.7.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nimble edge-community 0.14.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nimble 3.22-community 0.14.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable