FreeRTOS.FreeRTOS-Kernel is vulnerable to Use After Free
73
High Risk
On ARM TrustZone (ARMv8-M) configurations, SecureContext_FreeContext does not verify that the secure context being released belongs to a task that is no longer using it. An unprivileged Non-Secure task can free a secure context that is still active, leaving the task stack referencing deallocated secure-heap memory. Subsequent kernel operations write into the freed region and can corrupt other secure-heap allocations, causing crashes or unpredictable behavior. The fix adds a privilege and ownership check before the secure context is freed.
You are affected if you are using a version that falls within the vulnerable range and you build an ARM TrustZone (ARMv8-M) port with the MPU enabled that uses secure contexts.
FreeRTOS.FreeRTOS-Kernel is vulnerable to Use After Free in versions 10.2.0 - 11.3.0.
Upgrade the FreeRTOS.FreeRTOS-Kernel library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant