Vulnerability Description
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nimble | < 1.7.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2024/04/05/2Mailing List
- https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a52263Patch
- https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078Mailing List
- http://www.openwall.com/lists/oss-security/2024/04/05/2Mailing List
- https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a52263Patch
- https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078Mailing List
FAQ
What is CVE-2024-24746?
CVE-2024-24746 is a vulnerability with a CVSS score of 7.5 (HIGH). Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetoo...
How severe is CVE-2024-24746?
CVE-2024-24746 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-24746?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Nimble.