CVE-2024-51569: Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
Out-of-bounds Read vulnerability in Apache NimBLE.
Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51569?
CVE-2024-51569 is a medium severity vulnerability that could lead to out-of-bounds read issues.
How do I fix CVE-2024-51569?
To fix CVE-2024-51569, upgrade Apache NimBLE to version 1.7.0 or higher.
Who is affected by CVE-2024-51569?
CVE-2024-51569 affects users of Apache NimBLE versions prior to 1.7.0.
What causes CVE-2024-51569?
CVE-2024-51569 is caused by improper validation of HCI Number Of Completed Packets, leading to potential out-of-bounds access.
Is CVE-2024-51569 easy to exploit?
CVE-2024-51569 requires a broken or bogus Bluetooth controller for exploitation, making it less accessible.