Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Cybersecurity Classified by Officially
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/21/2026 10:30 AM PDT
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions.
incomplete command validation in the software timer command path allows an unprivileged task to reach a privileged code path that is intended to be invoked only internally, resulting in arbitrary code execution in a privileged kernel context and bypassing MPU-enforced task isolation. This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected.
missing privilege validation in the ARM TrustZone (ARMv8-M) secure-context handling allows an unprivileged Non-Secure task to free a task's secure context while it is still in use, resulting in a use-after-free of Secure-world memory and Secure-context corruption that typically causes a crash or undefined behavior. This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected.
missing size validation in the ARM TrustZone (ARMv8-M) secure-context allocation allows a Non-Secure task requesting a secure context with an undersized stack to trigger an out-of-bounds write into Secure-world memory, corrupting adjacent Secure-heap control structures and typically causing a crash or undefined behavior. This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-086-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 15, 2026 20:57
- Versions
- 2 recorded
- Identity
33336730c6639440c027e3f072f14d472be7dcb8