CVE-2024-47248: Apache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stack
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
Specially crafted MESH message could result in memory corruption when non-default build configuration is used. This issue affects Apache NimBLE: through 1.7.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47248?
CVE-2024-47248 is classified as a 'Classic Buffer Overflow' vulnerability that could result in memory corruption.
How do I fix CVE-2024-47248?
To mitigate CVE-2024-47248, update Apache NimBLE to the latest version beyond 1.7.0 or apply any security patches provided by the vendor.
Which versions of Apache NimBLE are affected by CVE-2024-47248?
CVE-2024-47248 affects all versions of Apache NimBLE up to and including 1.7.0.
What could be the impact of CVE-2024-47248 on my system?
Exploitation of CVE-2024-47248 could lead to abnormal application behavior, including potential crashes or memory corruption.
Is CVE-2024-47248 related to a specific build configuration?
Yes, CVE-2024-47248 can occur when using a non-default build configuration of Apache NimBLE.