Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver.
This issue affects Apache NimBLE: through 1.8.
This issue requires a broken or bogus Bluetooth controller and thus severity is considered low.
Users are recommended to upgrade to version 1.9, which fixes the issue.
{
"cna_assigner": "apache",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53470.json"
}{
"cpe": "cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.9.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53470.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "195062753234743226747269630964856657710",
"length": 1599
},
"id": "CVE-2025-53470-82604874",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/mynewt-nimble/commit/b973df0c6cf7b30efbf8eb2cafdc1ee843464b76",
"target": {
"file": "nimble/transport/common/hci_h4/src/hci_h4.c",
"function": "hci_h4_sm_w4_header"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"66536908622373870292629656214176091635",
"76763060761122660311126158760789099817",
"282262261505899381370371316599241633182",
"270460855469330194384128204579441502433"
],
"threshold": 0.9
},
"id": "CVE-2025-53470-c41f11ef",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/mynewt-nimble/commit/b973df0c6cf7b30efbf8eb2cafdc1ee843464b76",
"target": {
"file": "nimble/transport/common/hci_h4/src/hci_h4.c"
}
}
]
"2026-08-12T14:52:44Z"