VulnerabilityAnalyzed
CVE-2024-24746
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.
HIGH 7.5EPSS 1.45%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- apache/nimble
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2024/04/05/2Mailing List
- https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594Patch
- https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078Mailing List
- http://www.openwall.com/lists/oss-security/2024/04/05/2Mailing List
- https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594Patch
- https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.