HomeTencentCVE-2021-27439

CVE-2021-27439

HIGH
7.3CVSS
Published: 2022-05-03
Updated: 2024-11-21
AI Analysis

Description

TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
low
Integrity
low
Availability
low
Weaknesses
CWE-190

Metadata

Primary Vendor
TENCENT
Published
5/3/2022
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

tencent : tencentos-tiny

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-27439 | HIGH Severity | CVEDatabase.com | CVEDatabase.com