logo

Apache NuttX RTOS Patches Two Filesystem Flaws

ID: 15ffcec6-3578-57b1-9cdd-f6435e912343

STIX ID: report--15ffcec6-3578-57b1-9cdd-f6435e912343

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-01-01

Date Updated: 2026-04-22

Author: Ddos

...
...

Apache has published fixes for two filesystem vulnerabilities in the NuttX RTOS: CVE-2025-48769 (Use-After-Free, Moderate) in fs/vfs/fs_rename that can lead to heap corruption and unintended filesystem operations, and CVE-2025-48768 (Low) in fs/inode/fs_inoderemove that can enable root inode removal and result in NULL dereference or system crash; both are reachable on devices exposing virtual filesystem services and administrators should upgrade to 12.11.0 (for CVE-2025-48769) and 12.10.0 (for CVE-2025-48768) respectively.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.