漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
Vulnerability Description
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
Apache NimBLE 安全漏洞
Vulnerability Description
Apache NimBLE是美国阿帕奇(Apache)基金会的一个开源蓝牙 5.4 堆栈(主机和控制器),完全取代 Nordic 芯片组上的专有 SoftDevice。它是Apache Mynewt 项目的一部分。 Apache NimBLE 1.7.0版本及之前版本存在安全漏洞,该漏洞源于如果未正确验证 HCI 已完成数据包数,则在解析 HCI 事件时可能会导致越界访问,以及从 HCI 传输内存中读取无效数据。
CVSS Information
N/A
Vulnerability Type
N/A