CyberRota Analysis
AI-GeneratedFreeRTOS-Kernel versions prior to 11.3.1 are vulnerable due to insufficient minimum size validation in secure context allocation, which could allow local users to perform out-of-bounds writes and corrupt secure-world heap metadata. This vulnerability poses a high risk, as it can lead to potential exploitation of the secure environment. Organizations utilizing FreeRTOS-Kernel should prioritize upgrading to version 11.3.1 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later.
Related CVEs
Other vulnerabilities affecting the same vendor(s)