CVE-2024-24746

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

08 Apr 2024, 12:15

Type Values Removed Values Added
Summary
  • (es) Bucle con vulnerabilidad de condición de salida inalcanzable ("bucle infinito") en Apache NimBLE. La operación GATT especialmente manipulada puede causar un bucle infinito en el servidor GATT que lleva a la denegación de servicio en la pila o dispositivo Bluetooth. Este problema afecta a Apache NimBLE: hasta 1.6.0. Se recomienda a los usuarios actualizar a la versión 1.7.0, que soluciona el problema.
References
  • () https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594 -

06 Apr 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-06 12:15

Updated : 2024-04-10 09:15


NVD link : CVE-2024-24746

Mitre link : CVE-2024-24746

CVE.ORG link : CVE-2024-24746


JSON object : View

Products Affected

No product.

CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')