CVE-2021-27433: ARM mbed-ualloc memory library Integer Overflow or Wraparound
ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbedkrbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this ARM mbed-ualloc memory library vulnerability?
The vulnerability ID for this ARM mbed-ualloc memory library vulnerability is CVE-2021-27433.
What is the severity of CVE-2021-27433?
The severity of CVE-2021-27433 is critical, with a severity value of 9.8.
What is the affected software version for CVE-2021-27433?
The affected software version for CVE-2021-27433 is Arm Mbed Ualloc version 1.3.0.
What are the potential consequences of CVE-2021-27433?
The potential consequences of CVE-2021-27433 include arbitrary memory allocation, unexpected behavior such as a crash, or remote code injection/execution.
Are there any references to learn more about CVE-2021-27433?
Yes, you can find more information about CVE-2021-27433 at the following references: [GitHub Pull Request](https://github.com/ARMmbed/mbed-os/pull/14408) and [CISA Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04).