CVE-2021-27427: RIOT OS Integer Overflow or Wraparound
RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27427?
The severity of CVE-2021-27427 is significant due to its potential to lead to arbitrary memory allocation, crashes, or remote code execution.
How do I fix CVE-2021-27427?
To fix CVE-2021-27427, update RIOT OS to a version after 2020.01.1 that addresses this integer wrap-around vulnerability.
What systems are affected by CVE-2021-27427?
CVE-2021-27427 affects RIOT OS version 2020.01.1 and various other platforms including Amazon FreeRTOS and BlackBerry QNX OS.
What type of vulnerability is CVE-2021-27427?
CVE-2021-27427 is an integer wrap-around vulnerability related to the implementation of the calloc function.
Can CVE-2021-27427 be exploited remotely?
Yes, CVE-2021-27427 can potentially be exploited remotely, leading to memory allocation issues and unauthorized code execution.