PT-2024-19216 · Eclipse · Eclipse Threadx

0Xdea

+1

·

Published

2024-03-26

·

Updated

2025-02-11

·

CVE-2024-2212

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse ThreadX versions prior to 6.4.0
Description The issue arises from missing parameter checks in the xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API. This could lead to integer wraparound, under-allocations, and heap buffer overflows.
Recommendations For Eclipse ThreadX versions prior to 6.4.0, update to version 6.4.0 or later to resolve the issue. As a temporary workaround, consider disabling the xQueueCreate() and xQueueCreateSet() functions until a patch is available. Restrict access to the FreeRTOS compatibility API to minimize the risk of exploitation.

Fix

Memory Corruption

Integer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-2212
GHSA-V9JJ-7QJG-H6G6

Affected Products

Eclipse Threadx