Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xh2-4xwh-6pgr

Опубликовано: 09 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8

Описание

A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_select of the file rt-thread/components/lwp/lwp_syscall.c of the component Parameter Handler. The manipulation of the argument timeout leads to memory corruption. The vendor explains, that "[t]he timeout parameter should be checked to check if it can be accessed correctly in kernel mode and used temporarily in kernel memory."

A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_select of the file rt-thread/components/lwp/lwp_syscall.c of the component Parameter Handler. The manipulation of the argument timeout leads to memory corruption. The vendor explains, that "[t]he timeout parameter should be checked to check if it can be accessed correctly in kernel mode and used temporarily in kernel memory."

EPSS

Процентиль: 12%
0.0004
Низкий

8.6 High

CVSS4

8 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8
nvd
12 дней назад

A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_select of the file rt-thread/components/lwp/lwp_syscall.c of the component Parameter Handler. The manipulation of the argument timeout leads to memory corruption. The vendor explains, that "[t]he timeout parameter should be checked to check if it can be accessed correctly in kernel mode and used temporarily in kernel memory."

EPSS

Процентиль: 12%
0.0004
Низкий

8.6 High

CVSS4

8 High

CVSS3

Дефекты

CWE-119