Issue with FreeRTOS-Kernel - C... Note

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

AWS has announced important security vulnerabilities affecting FreeRTOS-Kernel, a real-time operating system kernel. Four distinct issues have been identified, each with specific conditions for impact. CVE-2026-77234 impacts configurations using the FreeRTOS MPU with software timers, excluding those without the MPU. CVE-2026-77235 and CVE-2026-77236 affect ARM TrustZone (ARMv8-M) configurations, but only when secure contexts are utilized. CVE-2026-77237 is specific to builds where queue sets are enabled, leaving applications without them unaffected. Affected versions for CVE-2026-77234 range from 7.0.0 to 11.3.0 for MPU-enabled ports. For ARMv8-M ports with TrustZone, versions 10.2.0 through 11.3.0 are impacted by the TrustZone-related CVEs. The queue set vulnerability, CVE-2026-77237, affects versions 7.4.0 to 11.3.0 on MPU-enabled ports with queue sets enabled. AWS urges users to consult the provided article for the most current and comprehensive details. This bulletin requires prompt attention to mitigate potential security risks.