First published: Tue Aug 31 2021(Updated: )
Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Tizen RT | <=3.0 | |
Amazon FreeRTOS | ||
Apache NuttX | ||
ARM CMSIS-RTOS2 | ||
Arm Mbed OS | ||
Arm Mbed ualloc | ||
QNX | ||
BlackBerry QNX OS for Safety | ||
BlackBerry QNX OS for Medical | ||
QNX | ||
Mongoose OS | ||
eCosCentric eCosPro RTOS | ||
Google Cloud IoT Device SDK | ||
MediaTek LinkIt SDK | ||
Micrium OS | ||
Micrium uC/OS | ||
NXP MCUXpresso SDK | ||
NXP MQX | ||
newlib | ||
RIOT OS | ||
Samsung Tizen RT | ||
TencentOS-tiny | ||
Texas Instruments SimpleLink CC32XX | ||
Texas Instruments SimpleLink MSP432E4 SDK | ||
Texas Instruments SimpleLink CC13X2 SDK | ||
Texas Instruments SimpleLink CC26XX | ||
Texas Instruments SimpleLink CC32XX | ||
uClibc | ||
Wind River VxWorks | ||
Zephyr Project RTOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22684 is classified as a medium severity vulnerability due to potential arbitrary memory allocation leading to unexpected behavior.
To fix CVE-2021-22684, update to the latest version of the affected software that addresses the integer wrap-around issue.
If exploited, CVE-2021-22684 can lead to arbitrary memory allocation, which may cause application crashes or unstable behavior.
CVE-2021-22684 affects various products including Samsung TizenRT and versions of FreeRTOS, NuttX, and others, typically prior to specific versions.
Currently, the best mitigation for CVE-2021-22684 is to upgrade the affected software to a version that has been patched to resolve the vulnerability.