CVE-2025-53470: Apache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver.
This issue affects Apache NimBLE: through 1.8.
This issue requires a broken or bogus Bluetooth controller and thus severity is considered low.
Users are recommended to upgrade to version 1.9, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53470?
The severity of CVE-2025-53470 is considered low, as it requires a broken or bogus Bluetooth controller.
How do I fix CVE-2025-53470?
To fix CVE-2025-53470, upgrade to a version of Apache NimBLE later than 1.8.
What type of vulnerability is CVE-2025-53470?
CVE-2025-53470 is classified as an Out-of-bounds Read vulnerability in the Apache NimBLE HCI H4 driver.
Which software versions are affected by CVE-2025-53470?
CVE-2025-53470 affects Apache NimBLE versions up to and including 1.8.
What could be the impact of exploiting CVE-2025-53470?
Exploiting CVE-2025-53470 could lead to invalid memory reads in the H4 driver, potentially causing instability.