CVE-2021-26461: malloc, realloc and memalign implementations are vulnerable to integer wrap-arounds
Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26461?
CVE-2021-26461 is considered a critical vulnerability due to its potential for arbitrary memory allocation and remote code execution.
How do I fix CVE-2021-26461?
To fix CVE-2021-26461, upgrade to Apache Nuttx version 10.1.0 or later.
What are the consequences of exploiting CVE-2021-26461?
Exploitation of CVE-2021-26461 can lead to unexpected behavior such as system crashes or remote code execution.
Which versions of software are affected by CVE-2021-26461?
CVE-2021-26461 affects Apache Nuttx versions prior to 10.1.0 and several other embedded operating systems and components.
What systems are vulnerable to CVE-2021-26461?
Systems using affected versions of Apache Nuttx, Amazon FreeRTOS, and other related platforms are vulnerable to CVE-2021-26461.