First published: Mon Jun 21 2021(Updated: )
Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache NuttX | <10.1.0 | |
Amazon FreeRTOS | ||
Apache NuttX | ||
ARM CMSIS-RTOS2 | ||
Arm Mbed OS | ||
Arm Mbed ualloc | ||
QNX | ||
BlackBerry QNX OS for Safety | ||
BlackBerry QNX OS for Medical | ||
QNX | ||
Mongoose OS | ||
eCosCentric eCosPro RTOS | ||
Google Cloud IoT Device SDK | ||
MediaTek LinkIt SDK | ||
Micrium OS | ||
Micrium uC/OS | ||
NXP MCUXpresso SDK | ||
NXP MQX | ||
newlib | ||
RIOT OS | ||
Samsung Tizen RT | ||
TencentOS-tiny | ||
Texas Instruments SimpleLink CC32XX | ||
Texas Instruments SimpleLink MSP432E4 SDK | ||
Texas Instruments SimpleLink CC13X2 SDK | ||
Texas Instruments SimpleLink CC26XX | ||
Texas Instruments SimpleLink CC32XX | ||
uClibc | ||
Wind River VxWorks | ||
Zephyr Project RTOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26461 is considered a critical vulnerability due to its potential for arbitrary memory allocation and remote code execution.
To fix CVE-2021-26461, upgrade to Apache Nuttx version 10.1.0 or later.
Exploitation of CVE-2021-26461 can lead to unexpected behavior such as system crashes or remote code execution.
CVE-2021-26461 affects Apache Nuttx versions prior to 10.1.0 and several other embedded operating systems and components.
Systems using affected versions of Apache Nuttx, Amazon FreeRTOS, and other related platforms are vulnerable to CVE-2021-26461.