PT-2024-19226 · Unknown · Eclipse Threadx
0Xdea
+1
·
Published
2024-03-26
·
Updated
2025-02-06
·
CVE-2024-2214
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse ThreadX versions prior to 6.4.0
Description
The issue is related to a missing array size check in the
Mtxinit() function within the Xtensa port of Eclipse ThreadX, causing a memory overwrite. The affected file is ports/xtensa/xcc/src/tx clib lock.c.Recommendations
For versions prior to 6.4.0, update to version 6.4.0 or later to resolve the issue.
As a temporary workaround, consider disabling the
Mtxinit() function until a patch is available.Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Threadx