CVE-2024-47248

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default build configuration is used. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*

History

08 Jul 2025, 14:18

Type Values Removed Values Added
First Time Apache nimble
Apache
CPE cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*
References () https://github.com/apache/mynewt-nimble/commit/4f75c0b3b466186beff40e8489870c6cee076aaa - () https://github.com/apache/mynewt-nimble/commit/4f75c0b3b466186beff40e8489870c6cee076aaa - Patch
References () https://lists.apache.org/thread/z8m7jqh54xybf9kz8q2l3tz92zsj7tmz - () https://lists.apache.org/thread/z8m7jqh54xybf9kz8q2l3tz92zsj7tmz - Vendor Advisory, Mailing List
References () http://www.openwall.com/lists/oss-security/2024/11/26/2 - () http://www.openwall.com/lists/oss-security/2024/11/26/2 - Mailing List, Vendor Advisory

06 Dec 2024, 11:15

Type Values Removed Values Added
References
  • () https://github.com/apache/mynewt-nimble/commit/4f75c0b3b466186beff40e8489870c6cee076aaa -

26 Nov 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de copia de búfer sin comprobar el tamaño de la entrada ('desbordamiento de búfer clásico') en Apache NimBLE. Un mensaje MESH especialmente manipulado podría provocar una corrupción de la memoria cuando se utiliza una configuración de compilación no predeterminada. Este problema afecta a Apache NimBLE: hasta la versión 1.7.0. Se recomienda a los usuarios que actualicen a la versión 1.8.0, que soluciona el problema.
References
  • () http://www.openwall.com/lists/oss-security/2024/11/26/2 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

26 Nov 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-26 12:15

Updated : 2025-07-08 14:18


NVD link : CVE-2024-47248

Mitre link : CVE-2024-47248

CVE.ORG link : CVE-2024-47248


JSON object : View

Products Affected

apache

  • nimble
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')