PT-2025-24409 · Rt-Thread · Rt-Thread

Zephyr Saxon

·

Published

2025-06-09

·

Updated

2025-06-14

·

CVE-2025-5866

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RT-Thread version 5.1.0
Description A critical vulnerability has been found in the sys sigprocmask function of the file rt-thread/components/lwp/lwp syscall.c. The manipulation of the how argument leads to improper validation of array index.
Recommendations For RT-Thread version 5.1.0, consider disabling the sys sigprocmask function until a patch is available to prevent exploitation of the how argument. Restrict access to the lwp syscall.c file to minimize the risk of improper array index validation. Avoid using the how argument in the sys sigprocmask function until the issue is resolved.

Exploit

Fix

Improper Validation of Array Index

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-5866

Affected Products

Rt-Thread