NuttX's Bluetooth HCI/UART stack users are advised to upgrade to version 12.9.0, which fixes the identified implementation issues.
This issue affects Apache NuttX: from 7.25 before 12.9.0.
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-16334 | Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache NuttX RTOS Bluetooth Stack (HCI and UART components) that may result in system crash, denial of service, or arbitrary code execution, after receiving maliciously crafted packets. NuttX's Bluetooth HCI/UART stack users are advised to upgrade to version 12.9.0, which fixes the identified implementation issues. This issue affects Apache NuttX: from 7.25 before 12.9.0. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Apache Apache nuttx | |
| CPEs | cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:* | |
| Vendors & Products | Apache Apache nuttx | 
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Mon, 26 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Mon, 26 May 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache NuttX RTOS Bluetooth Stack (HCI and UART components) that may result in system crash, denial of service, or arbitrary code execution, after receiving maliciously crafted packets. NuttX's Bluetooth HCI/UART stack users are advised to upgrade to version 12.9.0, which fixes the identified implementation issues. This issue affects Apache NuttX: from 7.25 before 12.9.0. | |
| Title | Apache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities. | |
| Weaknesses | CWE-119 CWE-121 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-28T03:56:07.159Z
Reserved: 2025-04-15T20:10:33.989Z
Link: CVE-2025-35003
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-05-26T10:47:55.245Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-05-26T10:15:19.750
Modified: 2025-07-08T13:17:42.373
Link: CVE-2025-35003
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.