Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent length
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.2%
exploitation probability
3.2%top 13% of all CVEs
observed exploitation
nono source reports it
Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.
Affected products
Apache Software Foundation · Apache NuttX (incubating)