https://seclists.org/oss-sec/2026/q1/41: CVE-2025-53477: Apache NimBLE: NULL Pointer Defence in NimBLE host HCI layer
Published Jan 8, 2026
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.8.0
Frequently Asked Questions
1
What is the severity of CVE-2025-53477?
The severity of CVE-2025-53477 is classified as low.
2
What versions of Apache NimBLE are affected by CVE-2025-53477?
Apache NimBLE versions through 1.8.0 are affected by CVE-2025-53477.
3
What does CVE-2025-53477 vulnerability entail?
CVE-2025-53477 is a NULL pointer dereference vulnerability due to missing validation in the HCI layer.
4
How can I fix CVE-2025-53477?
Fixing CVE-2025-53477 involves upgrading Apache NimBLE to a version beyond 1.8.0.
5
What conditions exacerbate the effects of CVE-2025-53477?
The effects of CVE-2025-53477 are exacerbated when asserts are disabled and invalid HCI commands are present.