NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
History

Mon, 12 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache nimble
Vendors & Products Apache
Apache nimble

Sat, 10 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
References

Sat, 10 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
Description NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Title Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer
Weaknesses CWE-476
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2026-01-10T09:45:27.630Z

Updated: 2026-01-12T16:54:48.496Z

Reserved: 2025-06-30T14:54:12.319Z

Link: CVE-2025-53477

cve-icon Vulnrichment

Updated: 2026-01-10T10:06:51.559Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-10T10:15:50.660

Modified: 2026-01-13T14:03:18.990

Link: CVE-2025-53477

cve-icon Redhat

No data.