CVE-2025-47868
Severity CVSS v4.0:
Pending analysis
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
16/06/2025
Last modified:
17/06/2025
Description
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RTOS nor Applications runtime, but active bdf-converter users may be affected when this tool is exposed to external provided user data data (i.e. publicly available automation).<br />
<br />
This issue affects Apache NuttX: from 6.9 before 12.9.0.<br />
<br />
Users are recommended to upgrade to version 12.9.0, which fixes the issue.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:* | 6.9 (including) | 12.9.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



