CVE-2024-51569

Name
CVE-2024-51569
Description
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://lists.apache.org/thread/q0vs5rddx1lho30xnpsrvpzgxqmywnhs
security@apache.org https://github.com/apache/mynewt-nimble/commit/4e3ac5b6e7c7df63a594c4ff6839e266b4ccfed9
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2024/11/26/5

Match rules

CPE URI Source package Min version Max version
apache-nimble >= 0 <= 1.7.0
cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:* nimble >= None < 1.8.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nimble edge-community 0.14.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nimble 3.22-community 0.14.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable