CVE-2021-27421: NXP MCUXpresso SDK Integer Overflow or Wraparound
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDKMalloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27421?
CVE-2021-27421 is a vulnerability in NXP MCUXpresso SDK versions prior to 2.8.2 that allows an attacker to access memory locations outside the bounds of a specified array.
How severe is CVE-2021-27421?
CVE-2021-27421 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
Which software versions are affected by CVE-2021-27421?
NXP MCUXpresso SDK versions prior to 2.8.2 are affected by CVE-2021-27421.
What is the impact of CVE-2021-27421?
CVE-2021-27421 can lead to unexpected behavior, such as segmentation faults, when assigning a specific block of memory from the heap.
How can CVE-2021-27421 be fixed?
To fix CVE-2021-27421, update to NXP MCUXpresso SDK version 2.8.2 or later.