Hi, Please find attached a security advisory that describes multiple vulnerabilities we discovered in RT-Thread RTOS. * Title: Multiple vulnerabilities in RT-Thread RTOS * OS: RT-Thread <= 5.0.2 * Author: Marco Ivaldi <marco.ivaldi () hnsecurity it> * Date: 2024-03-05 * CVE IDs and advisory URLs: * CVE-2024-24334 - https://github.com/RT-Thread/rt-thread/issues/8282 * CVE-2024-24335 - https://github.com/RT-Thread/rt-thread/issues/8271 * CVE-2024-25388 - https://github.com/RT-Thread/rt-thread/issues/8285 * CVE-2024-25389 - https://github.com/RT-Thread/rt-thread/issues/8283 * CVE-2024-25390 - https://github.com/RT-Thread/rt-thread/issues/8286 * CVE-2024-25391 - https://github.com/RT-Thread/rt-thread/issues/8287 * CVE-2024-25392 - https://github.com/RT-Thread/rt-thread/issues/8290 * CVE-2024-25393 - https://github.com/RT-Thread/rt-thread/issues/8288 * CVE-2024-25394 - https://github.com/RT-Thread/rt-thread/issues/8291 * CVE-2024-25395 - https://github.com/RT-Thread/rt-thread/issues/8289 * https://github.com/RT-Thread/rt-thread/issues/8292 * Vendor URL: https://www.rt-thread.io/ The advisory is also available at: https://github.com/hnsecurity/vulns/blob/main/HNS-2024-05-rt-thread.txt For additional information, please refer to our vulnerability writeup: https://security.humanativaspa.it/multiple-vulnerabilities-in-rt-thread-rtos Regards, -- Marco Ivaldi https://0xdeadbeef.info/ "When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl."
Attachment:
HNS-2024-05-rt-thread.txt
Description:
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/