CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

unknownCVE-2026-77234CVE-2026-77235CVE-2026-77236CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions. - CVE-2026-77234: This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected. - CVE-2026-77235: This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected. - CVE-2026-77236: This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected. - CVE-2026-77237: This issue affects builds with queue sets enabled; applications built without queue sets are not affected. Impacted versions: - CVE-2026-77234: >=7.0.0 AND <=11.3.0 (MPU-enabled ports) - CVE-2026-77235: >=10.2.0 AND <=11.3.0 (ARMv8-M ports with TrustZone + MPU) - CVE-2026-77236: >=10.2.0 AND <=11.3.0 (ARMv8-M ports with TrustZone) - CVE-2026-77237: >=7.4.0 AND <=11.3.0 (MPU-enabled ports with configUSE_QUEUE_SETS=1) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CSIRTS triage

vendor: AWSproduct: FreeRTOS-KernelPrivilege escalationMemory corruptionOtheraffected: Multiple versions (specific ranges not detailed)
What
Four privilege escalation and memory safety issues in FreeRTOS-Kernel affecting MPU, ARM TrustZone, and queue set configurations.
Who is affected
Microcontroller and embedded systems deployments using affected FreeRTOS-Kernel versions with MPU, ARM TrustZone secure contexts, or queue sets enabled.
Urgency
High; privilege escalation in embedded real-time systems can compromise device security and control; applicable only to specific configurations.
Action
Upgrade to patched FreeRTOS-Kernel version from AWS; verify if your build uses affected features (MPU, TrustZone, queue sets).

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch FreeRTOS-Kernel

Get an email when a new FreeRTOS-Kernel advisory drops — max one per day, one-click unsubscribe.

Details

Source
AWS Security Bulletins (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-086-aws/

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-77234coverage & exploitation statusNVD · CVE.org
CVE-2026-77235coverage & exploitation statusNVD · CVE.org
CVE-2026-77236coverage & exploitation statusNVD · CVE.org
CVE-2026-77237coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from AWS Security Bulletins