CVE-2025-48768
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/01/2026
Last modified:
01/01/2026
Description
Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the target architecture), or in general, a Denial of Service.<br />
<br />
This issue affects Apache NuttX RTOS: from 10.0.0 before 12.10.0.<br />
<br />
Users of filesystem based services with write access that were exposed over the network (i.e. FTP) are affected and recommended to upgrade to version 12.10.0 that fixes the issue.



