CVE-2021-27431

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
03/05/2022
Last modified:
13/05/2022

Description

ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arm:cmsis-rtos:*:*:*:*:*:*:*:* 2.1.3 (including)


References to Advisories, Solutions, and Tools