← Terug naar overzicht

A critical improper input validation vulnerability (CVE-2026-77234) has been identified in FreeRTOS-Kernel versions prior to 11.3.1. The flaw affects MPU-enabled ports and could allow an unprivileged task to execute arbitrary code in a privileged kernel context, effectively bypassing memory protection unit boundaries. This represents a significant privilege escalation risk in embedded and real-time operating system environments. The vulnerability is particularly concerning given FreeRTOS's widespread use in IoT and embedded systems. AWS has issued a security bulletin (2026-086-aws) acknowledging the issue. The remediation requires upgrading to FreeRTOS-Kernel version 11.3.1 or later, which is available on the official GitHub repository. No workarounds are mentioned; patching is the recommended course of action.

Affected products

  • FreeRTOS-Kernel

Related CVE's

  • CVE-2026-77234

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Operating Systems