VYPR
Unrated severityNVD Advisory· Published Sep 6, 2018· Updated Sep 16, 2024

CVE-2018-1000660

CVE-2018-1000660

Description

TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b85d contains a Insecure Permissions vulnerability in Function get_package_name in the file kernel/src/tbfheader.rs, variable "pub package_name: &'static str," in the file process.rs that can result in A tock capsule (untrusted driver) could access arbitrary memory by using only safe code. This vulnerability appears to have been fixed in commit 42f7f36e74088036068d62253e1d8fb26605feed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Tock/Tockinferred2 versions
    < 42f7f36e74088036068d62253e1d8fb26605feed+ 1 more
    • (no CPE)range: < 42f7f36e74088036068d62253e1d8fb26605feed
    • (no CPE)range: < commit 42f7f36e74088036068d62253e1d8fb26605feed

Patches

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.