First published: Tue May 03 2022(Updated: )
Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Micrium Os | <=5.10.1 | |
Multiple Amazon FreeRTOS, Version 10.4.1 | ||
Multiple Apache Nuttx OS, Version 9.1.0 | ||
Multiple ARM CMSIS-RTOS2, versions prior to 2.1.3 | ||
Multiple ARM Mbed OS, Version 6.3.0 | ||
Multiple ARM mbed-ualloc, Version 1.3.0 | ||
Multiple BlackBerry QNX SDP Versions 6.5.0 SP1 and earlier | ||
Multiple BlackBerry QNX OS for Safety Versions 1.0.1 and earlier safety products compliant with IEC 61508 and/or ISO 26262 | ||
Multiple BlackBerry QNX OS for Medical Versions 1.1 and earlier safety products compliant with IEC 62304 A full list of affected QNX products and versions is available here | ||
Multiple A full list of affected QNX products and versions is available here | ||
Multiple Cesanta Software Mongoose OS, v2.17.0 | ||
Multiple eCosCentric eCosPro RTOS, Versions 2.0.1 through 4.5.3 | ||
Multiple Google Cloud IoT Device SDK, Version 1.0.2 | ||
Multiple Media Tek LinkIt SDK, versions prior to 4.6.1 | ||
Multiple Micrium OS, Versions 5.10.1 and prior | ||
Multiple Micrium uC/OS: uC/LIB Versions 1.38.xx, Version 1.39.00 | ||
Multiple NXP MCUXpresso SDK, versions prior to 2.8.2 | ||
Multiple NXP MQX, Versions 5.1 and prior | ||
Multiple Redhat newlib, versions prior to 4.0.0 | ||
Multiple RIOT OS, Version 2020.01.1 | ||
Multiple Samsung Tizen RT RTOS, versions prior 3.0.GBB | ||
Multiple TencentOS-tiny, Version 3.1.0 | ||
Multiple Texas Instruments CC32XX, versions prior to 4.40.00.07 | ||
Multiple Texas Instruments SimpleLink MSP432E4XX | ||
Multiple Texas Instruments SimpleLink-CC13XX, versions prior to 4.40.00 | ||
Multiple Texas Instruments SimpleLink-CC26XX, versions prior to 4.40.00 | ||
Multiple Texas Instruments SimpleLink-CC32XX, versions prior to 4.10.03 | ||
Multiple Uclibc-NG, versions prior to 1.0.36 | ||
Multiple Windriver VxWorks, prior to 7.0 | ||
Multiple Zephyr Project RTOS, versions prior to 2.5 |
Update Micrium OS to v5.10.2 or later – Update available
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-27411.
The severity of CVE-2021-27411 is medium with a severity value of 6.5.
Micrium OS versions 5.10.1 and prior are affected by CVE-2021-27411.
CVE-2021-27411 can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated.
To fix CVE-2021-27411, it is recommended to update to a version of Micrium OS that is not affected by the vulnerability.