cancel
Showing results for 
Search instead for 
Did you mean: 

Newer ThreadX versions

mo_krauti
Associate II

Hello,

do you plan to release newer version of Eclipse ThreadX X-Cube packages?

We are using x-cube-azrtos-f7 1.1.0 which contains ThreadX V6.1.10 which is outdated and insecure.

Even remote code execution is possible: https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-m2rx-243p-9w64 and eclipse foundation only provides security support for ThreadX v6.4.x.

Sincerely

Mo

1 REPLY 1
Dor_RH
ST Employee

Hello @mo_krauti,

I reported this internally.

Internal ticket number: 209505 (This is an internal tracking number and is not accessible or usable by customers).

Thanks for your contribution.

Dor_RH