Your review has been sent successfully

RTOS Updates

1985
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

2 December, 2021

● High

2021-3966

All

Description:

Cisco has released security updates to address several vulnerabilities in products under the following Cisco categories:

  • Amazon FreeRTOS
    • Version 10.4.1
  • Apache Nuttx OS
    • Version 9.1.0 
  • ARM CMSIS-RTOS2
    • versions prior to 2.1.3
  • ARM Mbed OS
    • Version 6.3.0
  • ARM mbed-ualloc
    • Version 1.3.0
  • BlackBerry QNX SDP
    • Versions 6.5.0 SP1 and earlier
  • BlackBerry QNX OS for Safety
    • Versions 1.0.1 and earlier safety products compliant with IEC 61508 and/or ISO 26262
  • BlackBerry QNX OS for Medical
    • Versions 1.1 and earlier safety products compliant with IEC 62304
  • Cesanta Software Mongoose OS
    • v2.17.0
  • eCosCentric eCosPro RTOS
    • Versions 2.0.1 through 4.5.3
  • Google Cloud IoT Device SDK
    • Version 1.0.2
  • Media Tek LinkIt SDK
    • versions prior to 4.6.1
  • Micrium OS
    • Versions 5.10.1 and prior
  • Micrium uC/OS: uC/LIB
    • Versions 1.38.xx
    • Version 1.39.00
  • NXP MCUXpresso SDK
    • versions prior to 2.8.2
  • NXP MQX
    • Versions 5.1 and prior
  • Redhat newlib
    • versions prior to 4.0.0
  • RIOT OS
    • Version 2020.01.1 
  • Samsung Tizen RT RTOS
    • versions prior 3.0.GBB
  • TencentOS-tiny
    • Version 3.1.0
  • Texas Instruments CC32XX
  • versions prior to 4.40.00.07
  • Texas Instruments SimpleLink MSP432E4XX
  • Texas Instruments SimpleLink-CC13XX
  • versions prior to 4.40.00
  • Texas Instruments SimpleLink-CC26XX
  • versions prior to 4.40.00
  • Texas Instruments SimpleLink-CC32XX
    • versions prior to 4.10.03
  • Uclibc-NG
    • versions prior to 1.0.36 
  • Windriver VxWorks
    • prior to 7.0
  • Zephyr Project RTOS
    • versions prior to 2.5

Threats:

An attacker could exploit these vulnerabilities by doing the following:

  • Code injection
  • Buffer Overflow
  • Execute arbitrary code remotely
  • Memory corruption

Best practice and Recommendations:

Last updated at 2 December, 2021

Rate the content

rate-icon
up icon