Description
In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.
Problem types
CWE-233 Improper Handling of Parameters
Product status
Any version before 6.4.3
Credits
x-codingman (Saxon Mark)
References
github.com/...hreadx/security/advisories/GHSA-76hh-wrj5-hr2v