Hi,
Please find attached a security advisory that describes multiple
vulnerabilities we discovered in RT-Thread RTOS.
* Title: Multiple vulnerabilities in RT-Thread RTOS
* OS: RT-Thread <= 5.0.2
* Author: Marco Ivaldi <marco.ivaldi () hnsecurity it>
* Date: 2024-03-05
* CVE IDs and advisory URLs:
* CVE-2024-24334 - https://github.com/RT-Thread/rt-thread/issues/8282
* CVE-2024-24335 - https://github.com/RT-Thread/rt-thread/issues/8271
* CVE-2024-25388 - https://github.com/RT-Thread/rt-thread/issues/8285
* CVE-2024-25389 - https://github.com/RT-Thread/rt-thread/issues/8283
* CVE-2024-25390 - https://github.com/RT-Thread/rt-thread/issues/8286
* CVE-2024-25391 - https://github.com/RT-Thread/rt-thread/issues/8287
* CVE-2024-25392 - https://github.com/RT-Thread/rt-thread/issues/8290
* CVE-2024-25393 - https://github.com/RT-Thread/rt-thread/issues/8288
* CVE-2024-25394 - https://github.com/RT-Thread/rt-thread/issues/8291
* CVE-2024-25395 - https://github.com/RT-Thread/rt-thread/issues/8289
* https://github.com/RT-Thread/rt-thread/issues/8292
* Vendor URL: https://www.rt-thread.io/
The advisory is also available at:
https://github.com/hnsecurity/vulns/blob/main/HNS-2024-05-rt-thread.txt
For additional information, please refer to our vulnerability writeup:
https://security.humanativaspa.it/multiple-vulnerabilities-in-rt-thread-rtos
Regards,
--
Marco Ivaldi
https://0xdeadbeef.info/
"When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl."
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/