Описание
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
Ссылки
- ProductVendor Advisory
- Third Party AdvisoryUS Government Resource
- ProductVendor Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.2 (исключая)
cpe:2.3:a:nxp:mcuxpresso_software_development_kit:*:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00454
Низкий
7.3 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-190
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
EPSS
Процентиль: 63%
0.00454
Низкий
7.3 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-190