CVE-2024-2212
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Mar 26, 2024
Updated: Jun 10, 2024
CWE ID 20
Summary
CVE-2024-2212 is a vulnerability affecting Eclipse ThreadX before version 6.4.0. The issue lies in the xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API, specifically in the utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c file. These functions lack essential parameter checks, leading to potential risks such as integer wraparound, under-allocations, and heap buffer overflows.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.