CVE-2024-24746

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*

History

17 Jun 2025, 20:45

Type Values Removed Values Added
First Time Apache nimble
Apache
CWE CWE-835
CPE cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*
References () https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078 - () https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078 - Mailing List
References () http://www.openwall.com/lists/oss-security/2024/04/05/2 - () http://www.openwall.com/lists/oss-security/2024/04/05/2 - Mailing List
References () https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594 - () https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594 - Patch

01 May 2024, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/04/05/2 -

08 Apr 2024, 12:15

Type Values Removed Values Added
References
  • () https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594 -

06 Apr 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-06 12:15

Updated : 2025-06-17 20:45


NVD link : CVE-2024-24746

Mitre link : CVE-2024-24746


JSON object : View

Products Affected

apache

  • nimble
CWE

No CWE.