PT-2021-4214 · Texas Instruments · Simplelink

Published

2021-04-29

·

Updated

2023-12-01

·

CVE-2021-27504

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Texas Instruments SimpleLink series CC13XX, CC26XX, CC32XX, and MSP432E4 (affected versions not specified)
Description The issue is caused by an integer overflow in the implementation of the malloc() function in the FreeRTOS component of the software development kit for Texas Instruments microcontrollers. This can allow an attacker to execute arbitrary code or cause a denial of service. The vulnerability occurs when malloc() returns a valid pointer to a small buffer for extremely large values, triggering the integer overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2021-04817
CVE-2021-27504

Affected Products

Simplelink