CVE-2024-2214

HIGH

Eclipse ThreadX <6.4.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected file was ports/xtensa/xcc/src/tx_clib_lock.c

Scores

CVSS v3 7.0
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-129
Status published
Products (1)
eclipse/threadx < 6.4.0
Published Mar 26, 2024
Tracked Since Feb 18, 2026