|
Message-ID: <262c7ab7f2cbc14ba3fe9deb29d173067918b289.camel@apache.org> Date: Mon, 21 Jun 2021 08:37:01 -0700 From: Brennan Ashton <btashton@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2021-26461: Apache NuttX (incubating): malloc, realloc and memalign implementations are vulnerable to integer wrap-arounds Description: Apache Nuttx (incubating) versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. This issue is also known as BadAlloc Credit: Apache NuttX would like to thank Omri Ben-Bassat of Section 52 at Azure Defender for IoT of Microsoft Corp for bringing this issue to our attention. --Brennan Ashton
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.