PT-2025-24413 · Rt-Thread · Rt-Thread

Zephyr Saxon

·

Published

2025-06-09

·

Updated

2025-06-14

·

CVE-2025-5868

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RT-Thread version 5.1.0
Description A critical issue has been found in the function sys thread sigprocmask of the file rt-thread/components/lwp/lwp syscall.c. The manipulation of the argument how leads to improper validation of array index.
Recommendations For RT-Thread version 5.1.0, consider disabling the sys thread sigprocmask function until a patch is available to prevent improper validation of array index. Restrict access to the lwp syscall.c file to minimize the risk of exploitation. Avoid using the argument how in the affected function until the issue is resolved.

Exploit

Fix

Buffer Overflow

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2025-5868

Affected Products

Rt-Thread