CVE-2024-24746: Apache NimBLE: Denial of service in NimBLE Bluetooth stack
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.
Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device.
This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24746?
CVE-2024-24746 is classified as a denial of service vulnerability due to an infinite loop in the Apache NimBLE Bluetooth stack.
How can I mitigate the impact of CVE-2024-24746?
To mitigate CVE-2024-24746, it is recommended to upgrade Apache NimBLE to version 1.7.0 or later.
What software is affected by CVE-2024-24746?
CVE-2024-24746 affects Apache NimBLE versions up to and including 1.6.0.
Can CVE-2024-24746 be exploited remotely?
Yes, CVE-2024-24746 can be exploited remotely through specially crafted GATT operations.
What kind of impact does CVE-2024-24746 have on devices?
CVE-2024-24746 can lead to a denial of service by causing an infinite loop in the GATT server of the device.