First published: Wed May 12 2021(Updated: )
An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wind River VxWorks | >=6.9<6.9.4.12 | |
Wind River VxWorks | >=7.0<21.03 | |
Wind River VxWorks | =6.9.4.12 | |
Wind River VxWorks | =6.9.4.12-rolling_cumulative_patch_layer1 | |
Wind River VxWorks | =6.9.4.12-rolling_cumulative_patch_layer2 | |
oracle communications eagle | >=46.8.0<=46.8.2 | |
oracle communications eagle | >=46.9.1<=46.9.3 | |
oracle communications eagle | =46.7.0 | |
Amazon FreeRTOS | ||
Apache NuttX | ||
ARM CMSIS-RTOS2 | ||
Arm Mbed OS | ||
Arm Mbed ualloc | ||
QNX | ||
BlackBerry QNX OS for Safety | ||
BlackBerry QNX OS for Medical | ||
QNX | ||
Mongoose OS | ||
eCosCentric eCosPro RTOS | ||
Google Cloud IoT Device SDK | ||
MediaTek LinkIt SDK | ||
Micrium OS | ||
Micrium uC/OS | ||
NXP MCUXpresso SDK | ||
NXP MQX | ||
newlib | ||
RIOT OS | ||
Samsung Tizen RT | ||
TencentOS-tiny | ||
Texas Instruments SimpleLink CC32XX | ||
Texas Instruments SimpleLink MSP432E4 SDK | ||
Texas Instruments SimpleLink CC13X2 SDK | ||
Texas Instruments SimpleLink CC26XX | ||
Texas Instruments SimpleLink CC32XX | ||
uClibc | ||
Wind River VxWorks | ||
Zephyr Project RTOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35198 is a vulnerability in Wind River VxWorks 7 that could allow an attacker to cause memory corruption.
The severity of CVE-2020-35198 is critical, with a CVSS score of 9.8.
CVE-2020-35198 affects Wind River VxWorks 7 versions 6.9 to 6.9.4.12 and 7.0 to 21.03.
An attacker can exploit CVE-2020-35198 by crafting a malicious input that triggers an integer overflow in the memory allocator, leading to memory corruption.
Yes, Wind River has released patches to address CVE-2020-35198. It is recommended to update to the latest version of VxWorks 7 as soon as possible.