CVE-2024-47250

Name
CVE-2024-47250
Description
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://lists.apache.org/thread/zdb50spojlqbn0yxd866mbzqjt2vpt85
security@apache.org https://github.com/apache/mynewt-nimble/commit/23d61150ddae4bc8356356d7ef09d816fb89da45
security@apache.org https://github.com/apache/mynewt-nimble/commit/3b7a32ea09a3bffaab831ee0ab193a2375fc4df6
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2024/11/26/4

Match rules

CPE URI Source package Min version Max version
apache-nimble >= 0 <= 1.7.0
cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:* nimble >= None < 1.8.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nimble edge-community 0.14.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nimble 3.22-community 0.14.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable