{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-53477","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2025-06-30T14:54:12.319Z","datePublished":"2026-01-10T09:45:27.630Z","dateUpdated":"2026-01-12T16:54:48.496Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache Mynewt NimBLE","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"1.8.0","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"reporter","value":"雷重庆 <leicq@seu.edu.cn>"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>NULL Pointer Dereference vulnerability in Apache Nimble.</p><span style=\"background-color: rgb(255, 255, 255);\">Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference.</span><br>This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low.<br><br><p>This issue affects Apache NimBLE: through 1.8.0.</p><p>Users are recommended to upgrade to version 1.9.0, which fixes the issue.</p>"}],"value":"NULL Pointer Dereference vulnerability in Apache Nimble.\n\nMissing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference.\nThis issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low.\n\nThis issue affects Apache NimBLE: through 1.8.0.\n\nUsers are recommended to upgrade to version 1.9.0, which fixes the issue."}],"metrics":[{"other":{"content":{"text":"low"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-476","description":"CWE-476 NULL Pointer Dereference","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-01-10T09:45:27.630Z"},"references":[{"tags":["patch"],"url":"https://github.com/apache/mynewt-nimble/commit/0caf9baeb271ede85fcc5237ab87ddbf938600da"},{"tags":["patch"],"url":"https://github.com/apache/mynewt-nimble/commit/3160b8c4c7ff8db4e0f9badcdf7df684b151e077"},{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/1dxthc132hwm2tzvjblrtnschcsbw2vo"}],"source":{"discovery":"UNKNOWN"},"title":"Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/01/08/3"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-01-10T10:06:51.559Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-01-12T16:54:05.606645Z","id":"CVE-2025-53477","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-01-12T16:54:48.496Z"}}]}}