Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver.
This issue affects Apache NimBLE: through 1.8.
This issue requires a broken or bogus Bluetooth controller and thus severity is considered low.
Users are recommended to upgrade to version 1.9, which fixes the issue.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53470.json"
[
{
"id": "CVE-2025-53470-82604874",
"digest": {
"function_hash": "195062753234743226747269630964856657710",
"length": 1599.0
},
"signature_type": "Function",
"source": "https://github.com/apache/mynewt-nimble/commit/b973df0c6cf7b30efbf8eb2cafdc1ee843464b76",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "nimble/transport/common/hci_h4/src/hci_h4.c",
"function": "hci_h4_sm_w4_header"
}
},
{
"id": "CVE-2025-53470-c41f11ef",
"digest": {
"line_hashes": [
"66536908622373870292629656214176091635",
"76763060761122660311126158760789099817",
"282262261505899381370371316599241633182",
"270460855469330194384128204579441502433"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/apache/mynewt-nimble/commit/b973df0c6cf7b30efbf8eb2cafdc1ee843464b76",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "nimble/transport/common/hci_h4/src/hci_h4.c"
}
}
]