ThreadX security advisories

The table below lists published security advisories for ThreadX, newest first. Click a GHSA ID for full details.

Published GHSA ID CVE ID Summary Severity

2026‑01‑23

GHSA‑xj75‑fc68‑h4rw

CVE‑2026‑0648

Persistent Initialisation Pointer Corruption in the POSIX Compatibility Layer

High

2025‑10‑15

GHSA‑w8rw‑fqgj‑9r49

CVE‑2025‑55079

Module thread can get priority higer than txm_module_instance_maximum_priority

Medium

2025‑10‑15

GHSA‑76hh‑wrj5‑hr2v

CVE‑2025‑55080

Improper Parameter Check in ThreadX Syscall Implementation

High

2025‑10‑14

GHSA‑wcfg‑5jpf‑hhxq

CVE‑2025‑55078

A kernel object pointer validation flaw in ThreadX system calls allows attackers to supply pointers to reserved memory regions.

Medium

2024‑03‑26

GHSA‑vmp6‑qhp9‑r66x

CVE‑2024‑2214

Missing array size check in _Mtxinit() in the Xtensa port

High

2024‑03‑26

GHSA‑v9jj‑7qjg‑h6g6

CVE‑2024‑2212

Integer wraparounds, under-allocations, and heap buffer overflows in Eclipse ThreadX xQueueCreate() and xQueueCreateSet()

High

2023‑12‑03

GHSA‑p7w6‑62rq‑vrf9

CVE‑2023‑48693

Azure RTOS ThreadX Remote Code Execution Vulnerability

High