3.1
/ 10
LOW
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver.
This issue affects Apache NimBLE: through 1.8.
This issue requires a broken or bogus Bluetooth controller and thus severity is considered low.
Users are recommended to upgrade to version 1.9, which fixes the issue.
This issue affects Apache NimBLE: through 1.8.
This issue requires a broken or bogus Bluetooth controller and thus severity is considered low.
Users are recommended to upgrade to version 1.9, which fixes the issue.
Basic Information
ID
CVE-2025-53470
Source
apache
Published
Jan 10, 2026 at 09:46
Modified
Jan 12, 2026 at 19:12
Affected Product
Vendor
Apache Software Foundation
Product
Apache Mynewt NimBLE
Affected Versions
Apache Software Foundation Apache Mynewt NimBLE 0