PT-2022-9821 · Arm · Arm Mbed
Published
2022-05-03
·
Updated
2022-05-13
·
CVE-2021-27435
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ARM mbed product version 6.3.0
Description
The issue is related to an integer wrap-around in the
malloc wrapper function, which can lead to arbitrary memory allocation. This can result in unexpected behavior, such as a crash or remote code injection/execution.Recommendations
For ARM mbed product version 6.3.0, consider disabling the
malloc wrapper function as a temporary workaround until a patch is available. Restrict access to memory allocation functions to minimize the risk of exploitation.Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm Mbed