← Terug naar overzicht

CVE-2026-77236 is a vulnerability in FreeRTOS-Kernel versions prior to 11.3.1 involving missing minimum size validation in secure context allocation. The flaw may allow local users to corrupt secure-world heap metadata through an out-of-bounds write triggered by supplying an undersized stack size parameter. This affects the secure context allocation mechanism, potentially impacting systems relying on FreeRTOS TrustZone or secure-world isolation. The vulnerability is classified as a local privilege or integrity issue, as it requires local access to exploit. AWS has published a security bulletin acknowledging the issue. The fix is available in FreeRTOS-Kernel version 11.3.1 and later. Users and organizations using affected versions are strongly advised to upgrade immediately to remediate the risk.

Affected products

  • FreeRTOS-Kernel

Related CVE's

  • CVE-2026-77236

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Operating Systems