🔐 CVE Alert

CVE-2026-77235

HIGH 7.3

Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later.

CWE CWE-416
Vendor freertos
Product freertos-kernel
Published Aug 21, 2026
Last Updated Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for freertos freertos-kernel

Be the first to know when new high vulnerabilities affecting freertos freertos-kernel are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
High

Affected Versions

FreeRTOS / FreeRTOS-Kernel
10.2.0 ≤ 11.3.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/FreeRTOS/FreeRTOS-Kernel/releases/tag/V11.3.1 aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-086-aws/ github.com: https://github.com/FreeRTOS/FreeRTOS-Kernel/security/advisories/GHSA-55pf-q87x-c58c

Credits

NVIDIA