https://seclists.org/oss-sec/2024/q4/122: CVE-2024-51569: Apache NimBLE: Lack of input sanitization leading to out-of-bound ads in Number of Completed Packets HCI event handler
Published Nov 26, 2024
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.7.0
Frequently Asked Questions
1
What is the severity of CVE-2024-51569?
The severity of CVE-2024-51569 is classified as low.
2
What versions are affected by CVE-2024-51569?
CVE-2024-51569 affects Apache NimBLE versions up to and including 1.7.0.
3
What causes CVE-2024-51569?
CVE-2024-51569 is caused by a lack of input sanitization leading to an out-of-bounds read in the Number of Completed Packets HCI event handler.
4
How do I fix CVE-2024-51569?
To fix CVE-2024-51569, upgrade to a version of Apache NimBLE that includes input validation for the HCI event handler.
5
What is the potential impact of CVE-2024-51569?
The potential impact of CVE-2024-51569 includes invalid reads from HCI transport memory, which can lead to application instability.