Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later. | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later. |
Fri, 21 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Title | Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel | |
| First Time appeared |
Freertos
Freertos freertos-kernel |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:freertos:freertos-kernel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freertos
Freertos freertos-kernel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-21T19:42:23.681Z
Reserved: 2026-08-20T18:42:39.750Z
Link: CVE-2026-77235
No data.
Status : Received
Published: 2026-08-21T18:16:51.657
Modified: 2026-08-21T18:16:51.657
Link: CVE-2026-77235
No data.
OpenCVE Enrichment
No data.
Weaknesses