Missing Privilege Verification in FreeRTOS-Kernel Affects Secure Context Handling
CVE-2026-77235

8.3HIGH

Key Information:

Vendor

Freertos

Vendor
CVE Published:
21 August 2026

What is CVE-2026-77235?

The FreeRTOS-Kernel prior to version 11.3.1 contains a missing privilege verification in the secure context cleanup handler. This vulnerability may allow local users to exploit the system, resulting in a use-after-free condition within secure-world memory via the SVC handler responsible for secure context deallocation. To mitigate this risk, users should promptly upgrade to version 11.3.1 or later to ensure secure handling of context cleanup.

Affected Version(s)

FreeRTOS-Kernel 10.2.0 <= 11.3.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NVIDIA
.