Description
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.
Published: 2026-08-21
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation
Action: Patch Kernel
AI Analysis

Impact

Improper input validation in the timer command handler before version 11.3.1 allows an unprivileged task running on MPU‑enabled ports to execute code in privileged kernel context, constituting a privilege escalation flaw (CWE‑863). This can compromise confidentiality, integrity, and availability if an attacker can influence the timer command interface from user space.

Affected Systems

FreeRTOS‑Kernel versions earlier than 11.3.1 on MPU‑enabled ports. Systems that compile the kernel with MPU support and run those older releases are at risk; the fix is included in version 11.3.1 and later.

Risk and Exploitability

The CVSS score of 9.3 classifies the issue as critical. EPSS is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local; it requires an attacker to create or control an unprivileged task that issues malicious timer commands on a device with MPU enabled. Successful exploitation would elevate the task to privileged kernel context.

Generated by OpenCVE AI on August 21, 2026 at 19:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to FreeRTOS‑Kernel 11.3.1 or later, ensuring the build includes the patch for timer command handling.
  • If an upgrade cannot be applied immediately, reconfigure the system to disable MPU support on ports that use the timer command interface, or adjust the task configuration to prevent unprivileged tasks from issuing timer commands.
  • Enforce network isolation and least‑privilege boundaries for devices running vulnerable releases, limiting the potential impact of a privilege escalation event.

Generated by OpenCVE AI on August 21, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon freertos
CPEs cpe:2.3:o:amazon:freertos:*:*:*:*:*:*:*:*
Vendors & Products Amazon
Amazon freertos

Fri, 21 Aug 2026 20:00:00 +0000


Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

Fri, 21 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later
Title Improper input validation in FreeRTOS-Kernel timer command handling
First Time appeared Freertos
Freertos freertos-kernel
Weaknesses CWE-863
CPEs cpe:2.3:a:freertos:freertos-kernel:*:*:*:*:*:*:*:*
Vendors & Products Freertos
Freertos freertos-kernel
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Amazon Freertos
Freertos Freertos-kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-27T16:46:43.844Z

Reserved: 2026-08-20T18:42:39.352Z

Link: CVE-2026-77234

cve-icon Vulnrichment

Updated: 2026-08-27T16:06:24.379Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T18:16:51.507

Modified: 2026-08-27T20:18:39.130

Link: CVE-2026-77234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses