UAF via Missing Priv Verif in Secure Context Clean FreeRTOS-Kernel <11.3.1
CVE-2026-77235 Published on August 21, 2026

Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel
Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-77235 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and a high impact on availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
NONE
Integrity Impact:
LOW
Availability Impact:
HIGH

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2026-77235 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2026-77235

Want to know whenever a new CVE is published for Freertos Kernel? stack.watch will email you.

 

Affected Versions

FreeRTOS-Kernel: