NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-14175 NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
Fixes

Solution

Update NXP MCUXpresso SDK to 2.9.0 or later


Workaround

No workaround given by the vendor.

History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:24:46.545Z

Reserved: 2021-02-19T00:00:00.000Z

Link: CVE-2021-27421

cve-icon Vulnrichment

Updated: 2024-08-03T20:48:17.120Z

cve-icon NVD

Status : Modified

Published: 2022-05-03T21:15:08.307

Modified: 2024-11-21T05:57:57.357

Link: CVE-2021-27421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.