Description
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
No analysis available yet.
Remediation
Vendor Solution
Update NXP MCUXpresso SDK to 2.9.0 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-14175 | NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc. |
References
History
Wed, 16 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-16T16:24:46.545Z
Reserved: 2021-02-19T00:00:00.000Z
Link: CVE-2021-27421
Updated: 2024-08-03T20:48:17.120Z
Status : Modified
Published: 2022-05-03T21:15:08.307
Modified: 2024-11-21T05:57:57.357
Link: CVE-2021-27421
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD