Out-of-bounds write in FreeRTOS - CVE-2026-77236
Published: August 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in SecureContext_AllocateContext when allocating a secure context with an undersized stack on ARM TrustZone (ARMv8-M) configurations. A local user can request a secure context with an undersized stack to cause a denial of service.
Only ARM TrustZone (ARMv8-M) configurations that use secure contexts are affected.