PT-2024-20432 · Eclipse · Eclipse Threadx Netx Duo

0Xdea

+1

·

Published

2024-03-26

·

Updated

2025-02-06

·

CVE-2024-2452

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse ThreadX NetX Duo versions prior to 6.4.0
Description The issue arises when an attacker can control parameters of the portable aligned alloc() function, potentially causing an integer wrap-around and an allocation smaller than expected. This could lead to subsequent heap buffer overflows.
Recommendations For versions prior to 6.4.0, update to version 6.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the portable aligned alloc() function to minimize the risk of exploitation.

Fix

Integer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-2452
GHSA-H963-7VHW-8RPX

Affected Products

Eclipse Threadx Netx Duo