Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RTOS nor Applications runtime, but active bdf-converter users may be affected when this tool is exposed to external provided user data data (i.e. publicly available automation).

This issue affects Apache NuttX: from 6.9 before 12.9.0.

Users are recommended to upgrade to version 12.9.0, which fixes the issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18391 Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RTOS nor Applications runtime, but active bdf-converter users may be affected when this tool is exposed to external provided user data data (i.e. publicly available automation). This issue affects Apache NuttX: from 6.9 before 12.9.0. Users are recommended to upgrade to version 12.9.0, which fixes the issue.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache nuttx
CPEs cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache nuttx

Mon, 16 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 11:30:00 +0000

Type Values Removed Values Added
References

Mon, 16 Jun 2025 11:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RTOS nor Applications runtime, but active bdf-converter users may be affected when this tool is exposed to external provided user data data (i.e. publicly available automation). This issue affects Apache NuttX: from 6.9 before 12.9.0. Users are recommended to upgrade to version 12.9.0, which fixes the issue.
Title Apache NuttX RTOS: tools/bdf-converter.: tools/bdf-converter: Fix loop termination condition.
Weaknesses CWE-122
CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-06-16T16:12:13.504Z

Reserved: 2025-05-12T19:31:40.456Z

Link: CVE-2025-47868

cve-icon Vulnrichment

Updated: 2025-06-16T11:04:43.267Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-16T11:15:18.437

Modified: 2025-06-17T19:38:08.090

Link: CVE-2025-47868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.