CVE-2026-77234
Received Received - Intake

Improper Input Validation in FreeRTOS-Kernel Leading to Privilege Escalation

Vulnerability report for CVE-2026-77234, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: AMZN

Description

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to versionΒ 11.3.1 or later.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
freertos freertos_kernel 11.3.1
freertos freertos_kernel From 10.2.0 (inc) to 11.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper input validation in FreeRTOS-Kernel versions before 11.3.1. An unprivileged task on MPU-enabled ports could exploit this to execute code in the privileged kernel context, potentially gaining full system control.

Detection Guidance

This vulnerability is specific to FreeRTOS-Kernel versions before 11.3.1 and requires checking the kernel version. Use commands like 'grep FREERTOS_KERNEL_VERSION' in your build system or inspect the kernel source for version info. No direct network detection commands are provided in the context.

Impact Analysis

An attacker could exploit this to escalate privileges, execute arbitrary code, or take control of the system. This may lead to data breaches, system crashes, or unauthorized access to sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR and HIPAA requirements for data protection and access control. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Upgrade FreeRTOS-Kernel to version 11.3.1 or later to address improper input validation that could allow unprivileged tasks to execute privileged kernel code.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77234. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart