Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.
2023-11-21T18:15:07.713
2024-11-21T05:58:07.470
Modified
CVSSv3.1: 7.4 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | amazon | freertos | 10.4.1 | Yes |
Application | ti | simplelink_cc13xx_software_development_kit | < 4.40.00 | Yes |
Application | ti | simplelink_cc26xx_software_development_kit | < 4.40.00 | Yes |
Application | ti | simplelink_cc32xx_software_development_kit | < 4.10.03 | Yes |
Application | ti | simplelink_msp432e401y | - | Yes |
Application | ti | simplelink_msp432e411y | - | Yes |