Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-27504


Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.


Published

2023-11-21T18:15:07.713

Last Modified

2024-11-21T05:58:07.470

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-190
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System amazon freertos 10.4.1 Yes
Application ti simplelink_cc13xx_software_development_kit < 4.40.00 Yes
Application ti simplelink_cc26xx_software_development_kit < 4.40.00 Yes
Application ti simplelink_cc32xx_software_development_kit < 4.10.03 Yes
Application ti simplelink_msp432e401y - Yes
Application ti simplelink_msp432e411y - Yes

References