CVE-2021-27411

MEDIUM

Micrium OS <5.10.1 - Memory Corruption

Title source: llm
STIX 2.1

Description

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04
Product, Vendor Advisory x_refsource_confirm
https://www.silabs.com/developers/micrium-os

Scores

CVSS v3 6.5
EPSS 0.0079
EPSS Percentile 51.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (1)
silabs/micrium_os < 5.10.1
Published May 03, 2022
Tracked Since Feb 18, 2026