https://seclists.org/oss-sec/2026/q1/40: CVE-2025-53470: Apache NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
Published Jan 8, 2026
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.8
Frequently Asked Questions
1
What is the severity of CVE-2025-53470?
The severity of CVE-2025-53470 is classified as low.
2
What versions of Apache NimBLE are affected by CVE-2025-53470?
Apache NimBLE versions through 1.8 are affected by CVE-2025-53470.
3
How do I fix CVE-2025-53470?
To fix CVE-2025-53470, upgrade to a patched version of Apache NimBLE beyond 1.8.
4
What type of vulnerability is CVE-2025-53470?
CVE-2025-53470 is an out-of-bounds write vulnerability in the NimBLE HCI H4 driver.
5
What could be the impact of CVE-2025-53470?
CVE-2025-53470 could lead to invalid memory reads caused by specially crafted HCI events.