PT-2022-9263 · Nxp · Nxp Mqx
Published
2022-05-03
·
Updated
2022-05-11
·
CVE-2021-22680
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NXP MQX versions 5.1 and prior
Description
The issue is related to integer overflow in
mem alloc, lwmem alloc, and partition functions. This can lead to unverified memory assignment, resulting in arbitrary memory allocation and unexpected behavior, such as a crash or remote code injection/execution.Recommendations
For NXP MQX versions 5.1 and prior, consider restricting the use of the
mem alloc, lwmem alloc, and partition functions until a patch is available.
As a temporary workaround, implement additional validation and verification for memory allocation requests to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nxp Mqx