Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
Catalin Visinescu a3029acf95 drivers/contactless/mfrc522: Contactless Driver Is Not Robust
An attacker can specify an arbitrary page address when reading MIFARE tags.
Without validation, this could read beyond intended memory regions on the
tag, potentially causing a crash.

The mfrc522_mifare_read() command is also not robust and does not check
that the page address is valid. From section 7.6.5 of the *MIFARE Ultralight
contactless single-ticket IC
(https://www.nxp.com/docs/en/data-sheet/MF0ICU1.pdf) document:

>> The READ command needs the page address as a parameter. Only addresses
00h to 0Fh are decoded.

Testing: Builds fine.

Signed-off-by: Catalin Visinescu <catalin_visinescu@yahoo.com>
2026-07-02 09:38:49 +02:00
.github build(deps): bump actions/cache from 5 to 6 2026-06-29 12:59:18 +02:00
arch drivers: Fix comment typos — 'Pubic' → 'Public' across drivers and headers. 2026-07-02 13:29:48 +08:00
audio include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
binfmt fs/binfmt: Enforce POSIX execute permissions prior to binary load 2026-06-13 21:07:01 +08:00
boards stm32f746g-disco: Add support for Winbond W25Q128JVEQ flash chip 2026-07-02 09:36:23 +02:00
cmake build/fix: remove nonexistent target in cmake 2026-06-08 16:03:21 +08:00
crypto !nuttx: drop redundant casts on tv_sec/tv_nsec and fix printf formats 2026-05-19 16:21:28 +08:00
Documentation boards/esp32s3: add support to M5Stack Cardputer board 2026-07-02 13:27:20 +08:00
drivers drivers/contactless/mfrc522: Contactless Driver Is Not Robust 2026-07-02 09:38:49 +02:00
dummy build: add initial cmake build system 2023-07-08 13:50:48 +08:00
fs !include/fcntl.h: align open flags with Linux values 2026-06-30 13:43:44 +08:00
graphics !include/fcntl.h: align open flags with Linux values 2026-06-30 13:43:44 +08:00
include drivers: Fix comment typos — 'Pubic' → 'Public' across drivers and headers. 2026-07-02 13:29:48 +08:00
libs !include/fcntl.h: align open flags with Linux values 2026-06-30 13:43:44 +08:00
mm mm/gran: reject pools with too many granules 2026-06-24 08:41:28 -03:00
net !include/fcntl.h: align open flags with Linux values 2026-06-30 13:43:44 +08:00
openamp openamp: fix CMake dcache option 2026-05-10 15:03:24 +02:00
pass1 Makefile: Remove make depend files by make distclean 2026-02-16 16:27:57 +01:00
sched !include/fcntl.h: align open flags with Linux values 2026-06-30 13:43:44 +08:00
syscall syscall: fcntl param3 type to uintptr_t 2026-04-27 12:01:55 -03:00
tools arch/arm: add Realtek RTL8721Dx and RTL8720F (Ameba WHC) support 2026-07-01 09:18:06 -03:00
video video: ensure video library is non-empty 2026-05-08 19:51:39 +08:00
wireless include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines !boards: Remove NSH_ARCHINIT and board_app_initialize 2026-05-02 18:36:46 +08:00
.codespellrc arch/sim: replace macOS C++ constructor runtime hack with post-link patch 2026-05-19 07:08:55 -03:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore git: Specify multiple build directories in .gitignore. 2026-05-20 03:06:58 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.pre-commit-config.yaml pre-commit: enable codespell checks 2025-05-05 12:34:39 +08:00
.yamllint feat: add a GitHub action to lint the YAML files 2020-12-15 09:52:04 -06:00
AUTHORS AUTHORS: add Eren Terzioglu 2026-05-20 15:17:00 +08:00
CMakeLists.txt cmake/nuttx_toolchain.cmake: track preprocessed include deps 2026-06-04 17:22:43 +08:00
CONTRIBUTING.md docs: Fix typos, formatting, and numbering in README.md and CONTRIBUTING.md. 2026-03-23 12:05:24 +01:00
INVIOLABLES.md INVIOLABLES.md: Fix a simple alignment and change occurrences of Nuttx 2020-09-03 01:33:05 +08:00
Kconfig sched/misc/assert: Add CONFIG_SCHED_DUMP_TASKS and CONFIG_SCHED_DUMP_STACK 2026-06-09 08:04:54 -04:00
LICENSE !arch/stm32: move stm32l1 and finalize the directory split 2026-06-24 14:54:44 -03:00
Makefile tools: migrate to SPDX identifier 2024-09-10 23:11:11 +08:00
NOTICE Remove the double blank line from source files 2022-02-20 20:10:14 +01:00
README.md ci/testing: Add MemBrowse Integration 2026-06-18 12:07:41 -03:00
ReleaseNotes Documentation: move ReleaseNotes 2023-09-26 20:41:00 +08:00

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge MemBrowse

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.