CVE-2026-77237

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later.
Configurations

Configuration 1 (hide)

cpe:2.3:o:amazon:freertos:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-21 18:16

Updated : 2026-08-25 16:44


NVD link : CVE-2026-77237

Mitre link : CVE-2026-77237

CVE.ORG link : CVE-2026-77237


JSON object : View

Products Affected

amazon

  • freertos
CWE
CWE-125

Out-of-bounds Read

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')