NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
History

Sat, 10 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
References

Sat, 10 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
Description NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Title Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer
Weaknesses CWE-476
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-10T10:06:51.559Z

Reserved: 2025-06-30T14:54:12.319Z

Link: CVE-2025-53477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-10T10:15:50.660

Modified: 2026-01-10T10:15:50.660

Link: CVE-2025-53477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.