๐Ÿ” CVE Alert

CVE-2025-35003

CRITICAL 9.8

Apache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities.

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache NuttX RTOS Bluetooth Stack (HCI and UART components) that may result in system crash, denial of service, or arbitrary code execution, after receiving maliciously crafted packets. NuttX's Bluetooth HCI/UART stack users are advised to upgrade to version 12.9.0, which fixes the identified implementation issues. This issue affects Apache NuttX: from 7.25 before 12.9.0.

CWE CWE-119 CWE-121
Vendor apache software foundation
Product apache nuttx rtos
Published May 26, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache nuttx rtos

Be the first to know when new critical vulnerabilities affecting apache software foundation apache nuttx rtos are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache NuttX RTOS
7.25 < 12.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/nuttx/pull/16179 lists.apache.org: https://lists.apache.org/thread/k4xzz3jhkx48zxw9vwmqrmm4hmg78vsj openwall.com: http://www.openwall.com/lists/oss-security/2025/05/26/1

Credits

๐Ÿ” Chongqing Lei <[email protected]> ๐Ÿ” Zhen Ling <[email protected]> Chongqing Lei <[email protected]> Tomek CEDRO <[email protected]>