Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
Arnav Sharma 493031e7b1 drivers/mtd/mtd_config: fix UAF in mtdconfig_unregister_by_path
mtdconfig_unregister_by_path() opened the device with file_open(),
which runs mtdconfig_open() and therefore holds dev->lock for the
whole lifetime of the temporary file reference.  It then destroyed
the mutex and freed the private device structure while that
reference was still open, so the subsequent file_close() reached
mtdconfig_close(), which performs nxmutex_unlock() on freed memory.
Destroying a held mutex and unlocking it after free corrupt the heap;
on sim this crashes deterministically in the next allocation
(EXC_BAD_ACCESS in mm_malloc).  Both file_close() and
unregister_driver() return values were also discarded and the
function unconditionally returned OK, masking legitimate errors.

Reorder the teardown to close -> unregister -> destroy/free and
propagate errors, so that:

- file_close() (driver close callback and inode release) runs while
  the private device structure is still valid, releasing the
  exclusive access taken by mtdconfig_open(),
- the private structure is destroyed and freed only after
  unregister_driver() succeeds.  On failure the inode (and with it
  i_private) may still be referenced, so freeing would be wrong.
  Returning the error also honors the documented API contract
  (zero on success, negated errno on failure).

This matches the established close -> unregister -> teardown ordering
used by e.g. bchdev_unregister().

Verified with sim:configdata plus a register/unregister lifetime
exercise in examples/configdata: 934706/934706 checks pass with the
fix; with the fix stashed the same run dies with SIGSEGV right after
mtdconfig_unregister_by_path() returns.

Fixes: https://github.com/apache/nuttx/issues/20166
Signed-off-by: Arnav Sharma <2006arnavsharma@gmail.com>
2026-09-17 11:30:34 -03:00
.github ci: apply Depends-On dependencies to the memory report 2026-09-15 08:47:25 -03:00
arch arch/arm/n32h7: Add N32H762IIL7 BSP 2026-09-17 09:39:41 -03:00
audio audio: limit the buffer count guard to shared ring requests 2026-08-05 07:58:53 +02:00
binfmt libs/libc/elf, binfmt: Describe the GOT by base and size, not by index. 2026-09-08 16:31:16 -03:00
boards arch/arm/n32h7: Add N32H762IIL7 BSP 2026-09-17 09:39:41 -03:00
cmake cmake: fix undefined function name in parse args error messages 2026-09-11 21:15:22 +08:00
crypto tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
Documentation arch/arm/n32h7: Add N32H762IIL7 BSP 2026-09-17 09:39:41 -03:00
drivers drivers/mtd/mtd_config: fix UAF in mtdconfig_unregister_by_path 2026-09-17 11:30:34 -03:00
dummy
fs fs/inode: bound fdlist_extend() against the requested row 2026-09-17 13:50:27 +08:00
graphics graphics/nxterm: consume SGR escape sequences 2026-08-23 10:46:02 +08:00
include libc: add paths.h, sys/ttydefaults.h and termios IUTF8 2026-09-15 14:51:15 +02:00
libs libc/atexit: honor registrations made during exit processing 2026-09-14 18:52:46 -03:00
mm mm/pgalloc: support 32 KB and 64 KB page sizes 2026-09-10 23:28:43 +08:00
net net/pkt: clear pending TX IOB reference when poll callback finishes 2026-09-17 09:44:19 -03:00
openamp cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
pass1 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
sched sched/clock: Normalize CLOCK_FD getres errors. 2026-09-16 00:04:02 +08:00
syscall fs: rename PSEUDOFS_SOFTLINKS to FS_LINKS 2026-08-27 01:12:33 +08:00
tools tools: pass TOPDIR in SDIR_template and MAKE_template 2026-09-17 13:49:05 +08:00
video video/videomode: Fix EDID parsing and formatting of video mode dumps 2026-08-29 11:09:11 -03:00
wireless wireless/bluetooth: fix inverted MTU cap in bt_conn_send() 2026-08-30 10:48:18 -03:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines arch/arm: Reserve r10 via ARCHCFLAGS and hoist the PIC module flags. 2026-07-24 23:09:08 +08:00
.codespellrc Revert "zbus: Add linker support and documentation for the zbus port" 2026-08-30 10:45:19 -03:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore boards/risc-v/eic7700x: Adopt the common board layout. 2026-08-19 01:40:57 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.pre-commit-config.yaml
.yamllint
AUTHORS AUTHORS: add Jorge Guzman 2026-08-25 08:43:13 -04:00
CMakeLists.txt cmake: reconfigure when .config changes 2026-09-14 18:40:45 -03:00
CONTRIBUTING.md contributing: Add requirement for 'Assisted-by' commit field 2026-07-12 09:42:28 +08:00
INVIOLABLES.md
Kconfig include/nuttx: Add link-time iterable sections infrastructure 2026-08-27 01:04:05 +08:00
LICENSE libs/libdsp: Add Matrix operations 2026-07-11 14:55:59 -03:00
Makefile !boards: enforce secure ROMFS passwd and TEA key setup 2026-07-09 22:41:11 +08:00
NOTICE
README.md ci/testing: Add MemBrowse Integration 2026-06-18 12:07:41 -03:00
ReleaseNotes

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge MemBrowse

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.