Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27411

Опубликовано: 03 мая 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:silabs:micrium_os:*:*:*:*:*:*:*:*
Версия до 5.10.1 (включая)

EPSS

Процентиль: 44%
0.00212
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.5
github
почти 4 года назад

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.

EPSS

Процентиль: 44%
0.00212
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-190