PT-2026-79418 · Unknown · Freertos Kernel
CVSS v4.0
8.3
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreeRTOS-Kernel versions prior to 11.3.1
Description
Missing minimum size validation in secure context allocation allows local users to corrupt secure-world heap metadata. This occurs via an out-of-bounds write when an undersized stack size parameter is used within the
SecureContext AllocateContext() function.Recommendations
Upgrade to version 11.3.1 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freertos Kernel