CVE-2021-27208: Buffer Overflow

Published Mar 15, 2021
·
Updated

When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in from the parameter page is too large, this causes a buffer overflow that could lead to arbitrary code execution. Physical access and modification of the board assembly on which the Zynq-7000 SoC device mounted is needed to replace the original NAND flash memory with a NAND flash emulation device for this attack to be successful.

Affected Software

4 affected components
Xilinx Zynq-7000s Firmware
Xilinx Zynq-7000s
Xilinx Zynq-7000 Firmware
Xilinx Zynq-7000

Event History

Mar 15, 2021
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-27208?

CVE-2021-27208 is classified as a high severity vulnerability due to its potential to lead to arbitrary code execution.

2

How do I fix CVE-2021-27208?

To fix CVE-2021-27208, ensure that the firmware for the Xilinx Zynq-7000s and Zynq-7000 devices is updated to the latest secure version.

3

What types of devices are affected by CVE-2021-27208?

CVE-2021-27208 affects Xilinx Zynq-7000 and Zynq-7000s SoC devices that boot from NAND flash memory.

4

What is the nature of the vulnerability in CVE-2021-27208?

CVE-2021-27208 involves a buffer overflow caused by the NAND driver failing to validate input parameters from the parameter page during boot.

5

Are there any workarounds for CVE-2021-27208?

Currently, the recommended approach for CVE-2021-27208 is to apply the firmware updates as there are no known effective workarounds.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203