<!--X-Body-Begin-->
<!--X-User-Header-->
oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->
By Date
By Thread
</form>
<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
CVE-2024-24746: Apache NimBLE: Denial of service in NimBLE Bluetooth stack
<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->
From: Szymon Janc <janc () apache org>
Date: Fri, 05 Apr 2024 07:20:06 +0000
<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->
<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
Severity: important
Affected versions:
- Apache NimBLE through 1.6.0
Description:
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.
Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack
or device.
This issue affects Apache NimBLE: through 1.6.0.
Users are recommended to upgrade to version 1.7.0, which fixes the issue.
Credit:
Iván Arce from Quarkslab Vulnerability Reports team (reporter)
References:
https://mynewt.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-24746
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->
By Date
By Thread
Current thread:
CVE-2024-24746: Apache NimBLE: Denial of service in NimBLE Bluetooth stack Szymon Janc (Apr 05)
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->