https://seclists.org/oss-sec/2024/q4/119: CVE-2024-47248: Apache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stack
Published Nov 26, 2024
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.7.0
Frequently Asked Questions
1
What is the severity of CVE-2024-47248?
The severity of CVE-2024-47248 is classified as important.
2
Which versions of Apache NimBLE are affected by CVE-2024-47248?
Apache NimBLE versions up to and including 1.7.0 are affected by CVE-2024-47248.
3
What type of vulnerability is CVE-2024-47248?
CVE-2024-47248 is a buffer overflow vulnerability due to improper checking of input size.
4
How do I fix CVE-2024-47248?
To fix CVE-2024-47248, upgrade Apache NimBLE to a version greater than 1.7.0.
5
What can result from the vulnerability identified in CVE-2024-47248?
CVE-2024-47248 can lead to memory corruption when processing specially crafted MESH messages.