CVE-2026-77234
- EPSS 0.11%
- Veröffentlicht 21.08.2026 18:16:51
- Zuletzt bearbeitet 27.08.2026 20:18:39
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.
CVE-2026-77235
- EPSS 0.1%
- Veröffentlicht 21.08.2026 18:16:51
- Zuletzt bearbeitet 27.08.2026 20:18:39
Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate...
CVE-2026-77236
- EPSS 0.11%
- Veröffentlicht 21.08.2026 18:16:51
- Zuletzt bearbeitet 25.08.2026 16:44:28
Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, u...
CVE-2026-77237
- EPSS 0.12%
- Veröffentlicht 21.08.2026 18:16:51
- Zuletzt bearbeitet 25.08.2026 16:44:12
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgra...
CVE-2025-5688
- EPSS 0.32%
- Veröffentlicht 04.06.2025 17:15:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled. Users should upgrad...
CVE-2024-28115
- EPSS 0.24%
- Veröffentlicht 07.03.2024 21:15:08
- Zuletzt bearbeitet 21.11.2024 09:05:50
FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows ...
CVE-2021-27504
- EPSS 0.28%
- Veröffentlicht 21.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:07
Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.
CVE-2021-43997
- EPSS 0.32%
- Veröffentlicht 17.11.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:10
FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ...
CVE-2021-32020
- EPSS 1.3%
- Veröffentlicht 03.05.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:43
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.
CVE-2021-31571
- EPSS 1.38%
- Veröffentlicht 22.04.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:05:55
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.