Use After Free Vulnerability in Apache NuttX RTOS
CVE-2025-48769
What is CVE-2025-48769?
A Use After Free vulnerability has been identified in the Apache NuttX RTOS, specifically within the fs/vfs/fs_rename code. This vulnerability arises from a recursive implementation that utilizes a single buffer with two different pointer variables, allowing for arbitrary user-provided size buffer reallocation. Consequently, this mismanagement can lead to unintended results during virtual filesystem rename or move operations when the free heap chunk is accessed. Users, especially those operating virtual filesystem services with write access over network interfaces like FTP, are advised to upgrade to version 12.11.0, which addresses this critical issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache NuttX RTOS 7.20 < 12.11.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved