First published: Tue May 03 2022(Updated: )
Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose Os | =2.17.0 | |
Multiple Amazon FreeRTOS, Version 10.4.1 | ||
Multiple Apache Nuttx OS, Version 9.1.0 | ||
Multiple ARM CMSIS-RTOS2, versions prior to 2.1.3 | ||
Multiple ARM Mbed OS, Version 6.3.0 | ||
Multiple ARM mbed-ualloc, Version 1.3.0 | ||
Multiple BlackBerry QNX SDP Versions 6.5.0 SP1 and earlier | ||
Multiple BlackBerry QNX OS for Safety Versions 1.0.1 and earlier safety products compliant with IEC 61508 and/or ISO 26262 | ||
Multiple BlackBerry QNX OS for Medical Versions 1.1 and earlier safety products compliant with IEC 62304 A full list of affected QNX products and versions is available here | ||
Multiple A full list of affected QNX products and versions is available here | ||
Multiple Cesanta Software Mongoose OS, v2.17.0 | ||
Multiple eCosCentric eCosPro RTOS, Versions 2.0.1 through 4.5.3 | ||
Multiple Google Cloud IoT Device SDK, Version 1.0.2 | ||
Multiple Media Tek LinkIt SDK, versions prior to 4.6.1 | ||
Multiple Micrium OS, Versions 5.10.1 and prior | ||
Multiple Micrium uC/OS: uC/LIB Versions 1.38.xx, Version 1.39.00 | ||
Multiple NXP MCUXpresso SDK, versions prior to 2.8.2 | ||
Multiple NXP MQX, Versions 5.1 and prior | ||
Multiple Redhat newlib, versions prior to 4.0.0 | ||
Multiple RIOT OS, Version 2020.01.1 | ||
Multiple Samsung Tizen RT RTOS, versions prior 3.0.GBB | ||
Multiple TencentOS-tiny, Version 3.1.0 | ||
Multiple Texas Instruments CC32XX, versions prior to 4.40.00.07 | ||
Multiple Texas Instruments SimpleLink MSP432E4XX | ||
Multiple Texas Instruments SimpleLink-CC13XX, versions prior to 4.40.00 | ||
Multiple Texas Instruments SimpleLink-CC26XX, versions prior to 4.40.00 | ||
Multiple Texas Instruments SimpleLink-CC32XX, versions prior to 4.10.03 | ||
Multiple Uclibc-NG, versions prior to 1.0.36 | ||
Multiple Windriver VxWorks, prior to 7.0 | ||
Multiple Zephyr Project RTOS, versions prior to 2.5 |
Cesanta Software Mongoose update available
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27425 is a vulnerability in Cesanta Software Mongoose-OS v2.17.0 that allows for integer wrap-around in the function mm_malloc, leading to arbitrary memory allocation and potential remote code injection/execution.
CVE-2021-27425 has a severity rating of 9.8, which is considered critical.
The CVE-2021-27425 vulnerability can be exploited by triggering the integer wrap-around in the mm_malloc function, allowing for arbitrary memory allocation and potential remote code injection or execution.
CVE-2021-27425 affects Mongoose-OS version 2.17.0.
Currently, there are no known mitigations for CVE-2021-27425. It is recommended to update to a patched version of Mongoose-OS when available.