Amazon FreeRTOS 10.2.0 through 10.4.5 on the ARMv7-M and ARMv8-M MPU platforms does not prevent non-kernel code from calling the xPortRaisePrivilege and vPortResetPrivilege internal functions. This is fixed in 10.4.6 and in 10.4.3-LTS Patch 2.
References
| Link | Resource |
|---|---|
| https://github.com/FreeRTOS/FreeRTOS-Kernel/releases/tag/V10.4.6 | Release Notes Third Party Advisory |
| https://github.com/FreeRTOS/FreeRTOS-Kernel/releases/tag/V10.4.3-LTS-Patch-2 | Release Notes Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-11-17 21:15
Updated : 2021-11-23 16:03
NVD link : CVE-2021-43997
Mitre link : CVE-2021-43997
JSON object : View
Products Affected
amazon
- freertos
CWE
