Memory Access Vulnerability in FreeRTOS Kernel by Amazon Web Services
CVE-2026-77237
8.2HIGH
What is CVE-2026-77237?
In the FreeRTOS Kernel, prior to version 11.3.1, a vulnerability exists due to missing queue-set type validation in the function xQueueAddToSet(). This flaw may permit unprivileged tasks operating on MPU-enabled ports, when configured with configUSE_QUEUE_SETS=1, to access and read memory that is intended to be restricted to privileged kernel operations. Users are strongly advised to upgrade to version 11.3.1 or later to mitigate this security risk.
Affected Version(s)
FreeRTOS-Kernel 7.4.0 <= 11.3.0
