CVE-2024-2452: Integer wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc()
Published Mar 26, 2024
·Updated
In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of portablealignedalloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.
Affected Software
2 affected components
Eclipse threadx NetX Duo<6.4.0
Eclipse threadx NetX Duo<6.4.0
Remediation
Event History
Mar 26, 2024
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 21, 57075
Event
via NVD·07:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-2452?
CVE-2024-2452 is classified as a medium severity vulnerability due to its potential to cause heap buffer overflows.
2
How do I fix CVE-2024-2452?
To fix CVE-2024-2452, upgrade to Eclipse ThreadX NetX Duo version 6.4.0 or later.
3
What type of vulnerability is CVE-2024-2452?
CVE-2024-2452 is a heap buffer overflow vulnerability caused by integer wrap-around in memory allocation.
4
Who is affected by CVE-2024-2452?
CVE-2024-2452 affects users of Eclipse ThreadX NetX Duo versions prior to 6.4.0.
5
Can CVE-2024-2452 be exploited remotely?
Yes, CVE-2024-2452 can be exploited if an attacker can control parameters passed to the vulnerable function.