CVE-2021-27421
Summary
| CVE | CVE-2021-27421 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-03 21:15:00 UTC |
| Updated | 2022-05-12 16:00:00 UTC |
| Description | NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nxp | Mcuxpresso Software Development Kit | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple RTOS (Update D) | CISA | CONFIRM | www.cisa.gov | |
| Welcome | MCUXpresso SDK Builder | CONFIRM | mcuxpresso.nxp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: David Atch, Omri Ben Bassat, and Tamir Ariel from Microsoft Section 52, and the Azure Defender for IoT research group reported these vulnerabilities to CISA.
There are currently no legacy QID mappings associated with this CVE.