CVE-2021-27504

Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:amazon:freertos:10.4.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ti:simplelink_cc13xx_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_cc26xx_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_cc32xx_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_msp432e401y:-:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_msp432e411y:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:58

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-21-119-04 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-21-119-04 - Third Party Advisory, US Government Resource
References () https://www.ti.com/tool/TI-RTOS-MCU - Product () https://www.ti.com/tool/TI-RTOS-MCU - Product
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.4

01 Dec 2023, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Ti simplelink Cc26xx Software Development Kit
Ti simplelink Msp432e411y
Ti simplelink Cc13xx Software Development Kit
Amazon
Ti simplelink Cc32xx Software Development Kit
Ti simplelink Msp432e401y
Ti
Amazon freertos
CWE CWE-190
CPE cpe:2.3:a:ti:simplelink_msp432e401y:-:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_cc26xx_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_cc32xx_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_cc13xx_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ti:simplelink_msp432e411y:-:*:*:*:*:*:*:*
cpe:2.3:o:amazon:freertos:10.4.1:*:*:*:*:*:*:*
References () https://www.ti.com/tool/TI-RTOS-MCU - () https://www.ti.com/tool/TI-RTOS-MCU - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-21-119-04 - () https://www.cisa.gov/news-events/ics-advisories/icsa-21-119-04 - Third Party Advisory, US Government Resource

21 Nov 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-21 18:15

Updated : 2024-11-21 05:58


NVD link : CVE-2021-27504

Mitre link : CVE-2021-27504

CVE.ORG link : CVE-2021-27504


JSON object : View

Products Affected

ti

  • simplelink_cc32xx_software_development_kit
  • simplelink_cc26xx_software_development_kit
  • simplelink_msp432e401y
  • simplelink_cc13xx_software_development_kit
  • simplelink_msp432e411y

amazon

  • freertos
CWE
CWE-190

Integer Overflow or Wraparound