A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument to leads to null pointer dereference.
The product does not release or incorrectly releases a resource before it is made available for re-use.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://vuldb.com/?id.311626 | technical description third party advisory vdb entry |
https://vuldb.com/?ctiid.311626 | permissions required signature vdb entry |
https://vuldb.com/?submit.584129 | third party advisory vdb entry |
https://github.com/RT-Thread/rt-thread/issues/10299 | issue tracking exploit third party advisory |