CVE-2021-27439: TencentOS-tiny Integer Overflow or Wraparound
TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tosmmheapalloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-27439.
What is the severity of CVE-2021-27439?
The severity of CVE-2021-27439 is critical with a severity value of 9.8.
What is the affected software?
The affected software is TencentOS-tiny version 3.1.0.
How does CVE-2021-27439 affect the affected software?
CVE-2021-27439 allows for integer wrap-around in the function 'tos_mmheap_alloc' which can lead to arbitrary memory allocation and unexpected behavior such as a crash or remote code injection.
Is there a fix available for CVE-2021-27439?
Please refer to the reference link provided for information on available fixes for CVE-2021-27439.