CVE-2025-47868
published 2025-06-16CVE-2025-47868: Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RTOS nor Applications runtime, but active bdf-converter users may be affected when this tool is exposed to external provided user data data (i.e. publicly available automation).
This issue affects Apache NuttX: from 6.9 before 12.9.0.
Users are recommended to upgrade to version 12.9.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nuttx | >= 6.9 < 12.9.0 | 12.9.0 |
| apache_software_foundation | apache_nuttx_rtos_tools_bdf-converter | >= 6.9 < 12.9.0 | 12.9.0 |