CVE-2021-27411: Micrium OS Integer Overflow or Wraparound
Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions MemDynPoolCreate, MemDynPoolCreateHW and MemPoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-27411.
What is the severity of CVE-2021-27411?
The severity of CVE-2021-27411 is medium with a severity value of 6.5.
Which software versions are affected by CVE-2021-27411?
Micrium OS versions 5.10.1 and prior are affected by CVE-2021-27411.
How does CVE-2021-27411 impact memory allocation?
CVE-2021-27411 can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated.
How can I fix CVE-2021-27411?
To fix CVE-2021-27411, it is recommended to update to a version of Micrium OS that is not affected by the vulnerability.