A use-after-free vulnerability in the Apache NuttX real-time operating system (RTOS) was disclosed, allowing attackers to crash systems and perform unintended filesystem operations. The flaw, tracked as CVE-2025-48769, affects the virtual file system (VFS) component and is present in NuttX versions 7.20 through 12.10.0. Attackers exploiting this vulnerability could trigger arbitrary buffer reallocations and write operations to freed heap memory, leading to system instability, especially in environments where network-exposed services with write access are enabled.
The Apache NuttX development team has released version 12.11.0 to address these issues, following a coordinated disclosure and rigorous review process. Security experts strongly recommend that organizations using affected versions upgrade immediately to mitigate the risk of exploitation. The vulnerabilities were discovered by Richard Jiayang Liu and the fixes were integrated after review by NuttX maintainers, highlighting the importance of timely patching in embedded and IoT environments relying on NuttX RTOS.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting disclosed that CVE-2025-48769 affects Apache NuttX versions 7.20 through 12.10.0 and can let attackers crash systems or trigger unintended filesystem operations, particularly in network-exposed deployments with write access such as FTP servers. The reporting also noted responsible disclosure, availability of a patch in 12.11.0, and no evidence of active exploitation.
Apache NuttX RTOS addressed two filesystem-related flaws, including a use-after-free issue in the VFS rename functionality tracked as CVE-2025-48769. The fixes were released in NuttX version 12.11.0 to reduce the risk of crashes and unintended filesystem operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.