Home
HIGH: 7.2 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 6.4.3
affected
Description
In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.
Problem types
CWE-233 Improper Handling of Parameters
Product status
Any version before 6.4.3
Credits
x-codingman (Saxon Mark)
References
github.com/...hreadx/security/advisories/GHSA-76hh-wrj5-hr2v