{"id":"CVE-2021-27421","details":"NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.","modified":"2026-04-10T04:43:25.156295Z","published":"2022-05-03T21:15:08.307Z","references":[{"type":"ADVISORY","url":"https://mcuxpresso.nxp.com/en/welcome"},{"type":"ADVISORY","url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nxp-mcuxpresso/mcux-sdk","events":[{"introduced":"0"},{"fixed":"8abe276c392f547120c595134497153cc6b95919"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"2.8.2"}]}}],"versions":["MCUX_2.10.0","MCUX_2.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27421.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}