Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
🔗 CVE IDs covered (4)
📋 Description
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions. - CVE-2026-77234: This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected. - CVE-2026-77235: This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected. - CVE-2026-77236: This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use ARM TrustZone secure contexts are not affected. - CVE-2026-77237: This issue affects builds with queue sets enabled; applications built without queue sets are not affected.
Impacted versions: - CVE-2026-77234: >=7.0.0 AND - CVE-2026-77235: >=10.2.0 AND - CVE-2026-77236: >=10.2.0 AND - CVE-2026-77237: >=7.4.0 AND
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.