First published: Tue May 03 2022(Updated: )
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
NXP MCUXpresso SDK | <2.8.2 | |
Amazon FreeRTOS | ||
Apache NuttX | ||
ARM CMSIS-RTOS2 | ||
Arm Mbed OS | ||
Arm Mbed ualloc | ||
QNX | ||
BlackBerry QNX OS for Safety | ||
BlackBerry QNX OS for Medical | ||
QNX | ||
Mongoose OS | ||
eCosCentric eCosPro RTOS | ||
Google Cloud IoT Device SDK | ||
MediaTek LinkIt SDK | ||
Micrium OS | ||
Micrium uC/OS | ||
NXP MCUXpresso SDK | ||
NXP MQX | ||
newlib | ||
RIOT OS | ||
Samsung Tizen RT | ||
TencentOS-tiny | ||
Texas Instruments SimpleLink CC32XX | ||
Texas Instruments SimpleLink MSP432E4 SDK | ||
Texas Instruments SimpleLink CC13X2 SDK | ||
Texas Instruments SimpleLink CC26XX | ||
Texas Instruments SimpleLink CC32XX | ||
uClibc | ||
Wind River VxWorks | ||
Zephyr Project RTOS |
Update NXP MCUXpresso SDK to 2.9.0 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27421 is a vulnerability in NXP MCUXpresso SDK versions prior to 2.8.2 that allows an attacker to access memory locations outside the bounds of a specified array.
CVE-2021-27421 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
NXP MCUXpresso SDK versions prior to 2.8.2 are affected by CVE-2021-27421.
CVE-2021-27421 can lead to unexpected behavior, such as segmentation faults, when assigning a specific block of memory from the heap.
To fix CVE-2021-27421, update to NXP MCUXpresso SDK version 2.8.2 or later.