Vulnerability CVE-2021-27421


Published: 2022-05-03

Description:
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.

Type:

CWE-190

(Integer Overflow or Wraparound)

 References:
https://mcuxpresso.nxp.com/en/welcome
https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04

Copyright 2026, cxsecurity.com

 

Back to Top