CVE-2021-27502: Texas Instruments TI-RTOS Integer Overflow or Wraparound
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27502?
CVE-2021-27502 is a vulnerability in Texas Instruments TI-RTOS that can be exploited through an integer overflow or wraparound.
How does Texas Instruments TI-RTOS Integer Overflow or Wraparound vulnerability affect the software?
The vulnerability affects Texas Instruments TI-RTOS when configured to use the HeapMem heap, causing an integer overflow in 'HeapMem_allocUnprotected' function and potentially allowing for code execution.
What is the severity of CVE-2021-27502?
The severity of CVE-2021-27502 is high with a CVSS score of 7.4.
Which software versions are affected by Texas Instruments TI-RTOS Integer Overflow or Wraparound vulnerability?
The affected software versions include Ti Real-time Operating System, Ti Simplelink Cc13xx Software Development Kit (up to version 4.40.00), Ti Simplelink Cc26xx Software Development Kit (up to version 4.40.00), Ti Simplelink Cc32xx Software Development Kit (up to version 4.10.03), Ti Simplelink Msp432e401y, and Ti Simplelink Msp432e411y.
How do I mitigate the Texas Instruments TI-RTOS Integer Overflow or Wraparound vulnerability?
To mitigate the vulnerability, it is recommended to apply the necessary updates or patches provided by Texas Instruments and follow their security advisories.