CVE-2026-77237
EUVD-2026-6403421.08.2026, 18:16
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| amazon | freertos | 7.4.0 ≤ 𝑥 < 11.3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration