CVE-2025-35003 Information
May 27, 2025
cve
Description
Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache NuttX RTOS Bluetooth Stack (HCI and UART components) that may result in system crash denial of service or arbitrary code execution after receiving maliciously crafted packets.
NuttX’s Bluetooth HCI/UART stack users are advised to upgrade to version 12.9.0 which fixes the identified implementation issues.
This issue affects Apache NuttX: from 7.25 before 12.9.0.
Reference
http://www.openwall.com/lists/oss-security/2025/05/26/1 https://github.com/apache/nuttx/pull/16179 https://lists.apache.org/thread/k4xzz3jhkx48zxw9vwmqrmm4hmg78vsj
Share on: