CVE: CVE-2025-53477 Component: Apache NimBLE Vulnerability Type: NULL Pointer Dereference in NimBLE host HCI layer Severity: Low Affected Versions: Apache NimBLE through 1.8.0 Description: Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller. Mitigation: Upgrade to version 1.9.0 Credit: 雷重庆 (reporter) References: - https://github.com/apache/mynewt-nimble/commit/0caf9baeb271ede85fcc5237ab87ddbf938600da - https://github.com/apache/mynewt-nimble/commit/3160b8c4c7ff8db4e0f9badcdf7df684b151e077 - https://mynewt.apache.org/ - https://www.cve.org/CVERecord?id=CVE-2025-53477