CVE-2021-22680: NXP MQX Integer Overflow or Wraparound
NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in memalloc, lwmemalloc and partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-22680?
CVE-2021-22680 is a vulnerability in NXP MQX Versions 5.1 and prior that allows for integer overflow in memory allocation functions, leading to unexpected behavior or remote code execution.
How severe is CVE-2021-22680?
CVE-2021-22680 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
Which software versions are affected by CVE-2021-22680?
NXP MQX Versions 5.1 and prior are affected by CVE-2021-22680.
What are the potential consequences of CVE-2021-22680?
CVE-2021-22680 can result in unexpected behavior, such as crashes, and can also allow for remote code injection or execution.
Is there a fix available for CVE-2021-22680?
At the time of this writing, there is no known fix or patch available for CVE-2021-22680. It is recommended to follow the guidance provided by NXP or the official sources for updates and mitigation measures.