First published: Thu Apr 22 2021(Updated: )
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon FreeRTOS | <10.4.3 | |
Amazon FreeRTOS | ||
Apache NuttX | ||
ARM CMSIS-RTOS2 | ||
Arm Mbed OS | ||
Arm Mbed ualloc | ||
QNX | ||
BlackBerry QNX OS for Safety | ||
BlackBerry QNX OS for Medical | ||
QNX | ||
Mongoose OS | ||
eCosCentric eCosPro RTOS | ||
Google Cloud IoT Device SDK | ||
MediaTek LinkIt SDK | ||
Micrium OS | ||
Micrium uC/OS | ||
NXP MCUXpresso SDK | ||
NXP MQX | ||
newlib | ||
RIOT OS | ||
Samsung Tizen RT | ||
TencentOS-tiny | ||
Texas Instruments SimpleLink CC32XX | ||
Texas Instruments SimpleLink MSP432E4 SDK | ||
Texas Instruments SimpleLink CC13X2 SDK | ||
Texas Instruments SimpleLink CC26XX | ||
Texas Instruments SimpleLink CC32XX | ||
uClibc | ||
Wind River VxWorks | ||
Zephyr Project RTOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31571 is a vulnerability in the kernel of Amazon Web Services FreeRTOS before version 10.4.3 which allows an integer overflow in queue.c for queue creation.
The severity of CVE-2021-31571 is critical with a CVSS score of 9.8.
CVE-2021-31571 affects Amazon Freertos before version 10.4.3 by causing an integer overflow in the creation of queues.
Yes, the fix for CVE-2021-31571 is available in version 10.4.3 of Amazon Freertos.
You can find more information about CVE-2021-31571 on the GitHub page for FreeRTOS-Kernel: https://github.com/FreeRTOS/FreeRTOS-Kernel/commit/47338393f1f79558f6144213409f09f81d7c4837