ZeroHour

CVE-2021-27411

CVSS 3.1
6.5 medium
EPSS
<1%p57
Published
()
Modified
Description

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.

Vendors
silabs
Products
micrium os
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.