Texas Instruments TI-RTOS, when configured to use HeapMem heap(default),
malloc returns a valid pointer to a small buffer on extremely large
values, which can trigger an integer overflow vulnerability in
'HeapMem_allocUnprotected' and result in code execution.

Project Subscriptions

Vendors Products
Cc3220r Subscribe
Cc3220s Subscribe
Cc3220sf Subscribe
Cc3230s Subscribe
Cc3230sf Subscribe
Cc3235s Subscribe
Cc3235sf Subscribe
Real-time Operating System Subscribe
Simplelink Cc13xx Software Development Kit Subscribe
Simplelink Cc26xx Software Development Kit Subscribe
Simplelink Cc32xx Software Development Kit Subscribe
Simplelink Msp432e401y Subscribe
Simplelink Msp432e411y Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-14256 Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.
Fixes

Solution

Texas Instruments CC32XX – Update to v4.40.00.07 Texas Instruments SimpleLink CC13X0 – Update to v4.10.03 https://www.ti.com/technologies/security/report-product-security-vulnerabilities.html Texas Instruments SimpleLink CC13X2-CC26X2 – Update to v4.40.00 https://www.ti.com/technologies/security/report-product-security-vulnerabilities.html Texas Instruments SimpleLink CC2640R2 – Update to v4.40.00 https://www.ti.com/technologies/security/report-product-security-vulnerabilities.html Texas Instruments SimpleLink MSP432E4 – Confirmed. No update currently planned


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-03T21:26:09.047Z

Reserved: 2021-02-19T17:45:42.346Z

Link: CVE-2021-27502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-21T18:15:07.510

Modified: 2024-11-21T05:58:07.200

Link: CVE-2021-27502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses