← Back

CVE-2021-22636

nvd nist
Published: Nov 20, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.

Affected (6)

6 products
Real Time Operating System
Simplelink Msp432e401y
Simplelink Msp432e411y
Configuration A
1 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Ti
Cc3200
All versions
Ti
Cc3220r
All versions
Ti
Cc3220s
All versions
Ti
Cc3220sf
All versions
Ti
Cc3230s
All versions
Ti
Cc3230sf
All versions
Ti
Cc3235s
All versions
Ti
Cc3235sf
All versions
Configuration B
5 vulnerable

References (4)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: ics-cert@hq.dhs.gov
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.