CVE-2024-24746

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/04/05/2 - () http://www.openwall.com/lists/oss-security/2024/04/05/2 -
References () https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594 - () https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594 -
References () https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078 - () https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078 -

22 Aug 2024, 14:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

01 May 2024, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/04/05/2 -

08 Apr 2024, 12:15

Type Values Removed Values Added
References
  • () https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594 -
Summary
  • (es) Bucle con vulnerabilidad de condición de salida inalcanzable ("bucle infinito") en Apache NimBLE. La operación GATT especialmente manipulada puede causar un bucle infinito en el servidor GATT que lleva a la denegación de servicio en la pila o dispositivo Bluetooth. Este problema afecta a Apache NimBLE: hasta 1.6.0. Se recomienda a los usuarios actualizar a la versión 1.7.0, que soluciona el problema.

06 Apr 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-06 12:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24746

Mitre link : CVE-2024-24746

CVE.ORG link : CVE-2024-24746


JSON object : View

Products Affected

No product.

CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')