CVE-2025-48768

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/01/2026
Last modified:
01/01/2026

Description

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the target architecture), or in general, a Denial of Service.<br /> <br /> This issue affects Apache NuttX RTOS: from 10.0.0 before 12.10.0.<br /> <br /> Users of filesystem based services with write access that were exposed over the network (i.e. FTP) are affected and recommended to upgrade to version 12.10.0 that fixes the issue.

Impact