PT-2026-1815 · Apache · Apache Nimble
Published
2026-01-10
·
Updated
2026-01-10
·
CVE-2025-53470
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NimBLE versions through 1.8
Description
An out-of-bounds read issue exists in the Apache NimBLE HCI H4 driver. A specially crafted HCI event can cause an invalid memory read within the H4 driver. The issue is considered low severity as it requires a malfunctioning Bluetooth controller.
Recommendations
Upgrade to version 1.9 to resolve the issue.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nimble