PT-2026-79426 · Unknown · Freertos Kernel
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRTOS-Kernel versions prior to 11.3.1
Description
Missing queue-set type validation in the
xQueueAddToSet() function may allow an unprivileged task to read privileged kernel memory. This issue occurs on MPU-enabled ports when configUSE QUEUE SETS is set to 1. MPU (Memory Protection Unit) is a hardware component that monitors memory access to prevent unauthorized access to specific memory regions.Recommendations
Upgrade to version 11.3.1 or later.
Fix
Type Confusion
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freertos Kernel