CVE-2025-48768 (CNNVD-202601-023)
中文标题:
Apache NuttX 安全漏洞
英文标题:
Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal
漏洞描述
中文描述:
Apache NuttX是美国阿帕奇(Apache)基金会的一套实时嵌入式操作系统。 Apache NuttX 12.10.0之前版本存在安全漏洞,该漏洞源于释放无效指针或引用,可能导致拒绝服务攻击。
英文描述:
Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the target architecture), or in general, a Denial of Service. This issue affects Apache NuttX RTOS: from 10.0.0 before 12.10.0. Users of filesystem based services with write access that were exposed over the network (i.e. FTP) are affected and recommended to upgrade to version 12.10.0 that fixes the issue.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Apache Software Foundation | Apache NuttX RTOS | - | < 12.10.0 | - |
cpe:2.3:a:apache_software_foundation:apache_nuttx_rtos:*:*:*:*:*:*:*:*
|
| apache | nuttx | * | - | - |
cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (adp)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-48768 |
2026-01-07 02:47:02 | 2026-01-12 02:11:53 |
| NVD | nvd_CVE-2025-48768 |
2026-01-07 03:00:03 | 2026-01-12 02:27:50 |
| CNNVD | cnnvd_CNNVD-202601-023 |
2026-01-11 06:15:06 | 2026-01-12 02:38:11 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-023
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- references_count: 2 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']