Apache NimBLE:缺乏输入清理,导致“已完成数据包数”HCI 事件处理程序中出现越界读取(CVE-2024-51569)
CVE编号
CVE-2024-51569
利用情况
暂无
补丁情况
N/A
披露时间
2024-11-26
漏洞描述
Out-of-bounds Read vulnerability in Apache NimBLE.
Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory.
This issue requires broken or bogus Bluetooth controller and thus severity is considered low.
This issue affects Apache NimBLE: through 1.7.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
文章评论