ZeroHour

CVE-2021-27504

CVSS 3.1
7.8 high
EPSS
<1%p20
Published
()
Modified
Description

Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.

Vendors
amazonti
Products
freertos, simplelink cc13xx software development kit, simplelink cc26xx software development kit, simplelink cc32xx software development kit, simplelink msp432e401y, simplelink msp432e411y
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.