malloc returns a valid pointer to a small buffer on extremely large
values, which can trigger an integer overflow vulnerability in
'HeapMem_allocUnprotected' and result in code execution.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ti
Subscribe
|
Cc3200
Subscribe
Cc3220r
Subscribe
Cc3220s
Subscribe
Cc3220sf
Subscribe
Cc3230s
Subscribe
Cc3230sf
Subscribe
Cc3235s
Subscribe
Cc3235sf
Subscribe
Real-time Operating System
Subscribe
Simplelink Cc13xx Software Development Kit
Subscribe
Simplelink Cc26xx Software Development Kit
Subscribe
Simplelink Cc32xx Software Development Kit
Subscribe
Simplelink Msp432e401y
Subscribe
Simplelink Msp432e411y
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-14256 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution. |
Solution
Texas Instruments CC32XX – Update to v4.40.00.07 Texas Instruments SimpleLink CC13X0 – Update to v4.10.03 https://www.ti.com/technologies/security/report-product-security-vulnerabilities.html Texas Instruments SimpleLink CC13X2-CC26X2 – Update to v4.40.00 https://www.ti.com/technologies/security/report-product-security-vulnerabilities.html Texas Instruments SimpleLink CC2640R2 – Update to v4.40.00 https://www.ti.com/technologies/security/report-product-security-vulnerabilities.html Texas Instruments SimpleLink MSP432E4 – Confirmed. No update currently planned
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-03T21:26:09.047Z
Reserved: 2021-02-19T17:45:42.346Z
Link: CVE-2021-27502
No data.
Status : Modified
Published: 2023-11-21T18:15:07.510
Modified: 2024-11-21T05:58:07.200
Link: CVE-2021-27502
No data.
OpenCVE Enrichment
No data.
EUVD