Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 21 Jun 2021 08:37:01 -0700
From: Brennan Ashton <btashton@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2021-26461: Apache NuttX (incubating): malloc, realloc and
 memalign implementations are vulnerable to integer wrap-arounds

Description:

Apache Nuttx (incubating) versions prior to 10.1.0 are vulnerable to
integer wrap-around in functions malloc, realloc and memalign. This
improper memory assignment can lead to arbitrary memory allocation,
resulting in unexpected behavior such as a crash or a remote code
injection/execution. 

This issue is also known as BadAlloc

Credit:

Apache NuttX would like to thank Omri Ben-Bassat of Section 52 at Azure
Defender for IoT of Microsoft Corp for bringing this issue to our
attention.

--Brennan Ashton

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.