FreeRTOS.FreeRTOS-Kernel is vulnerable to Privilege Escalation
88
High Risk
FreeRTOS-Kernel validates software timer commands incompletely on MPU-enabled ports. An unprivileged task can submit a crafted timer command that reaches a privileged code path intended to be invoked only internally by the kernel. This lets the unprivileged task make the privileged timer service task execute an arbitrary function, running code in the privileged kernel context and bypassing MPU task isolation. The fix adds range and privilege validation to the timer command handling path.
You are affected if you are using a version that falls within the vulnerable range and you build an MPU-enabled port with FreeRTOS software timers enabled.
FreeRTOS.FreeRTOS-Kernel is vulnerable to Privilege Escalation in versions 7.0.0 - 11.3.0.
Upgrade the FreeRTOS.FreeRTOS-Kernel library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant