{"id":"UBUNTU-CVE-2021-3420","details":"A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.","modified":"2026-04-22T12:54:56.125090Z","published":"2021-03-05T21:15:00Z","upstream":["CVE-2021-3420"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3420"},{"type":"REPORT","url":"https://sourceware.org/git/?p=newlib-cygwin.git;a=commit;h=aa106b29a6a8a1b0df9e334704292cbc32f2d44e"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-3420"}],"affected":[{"package":{"name":"newlib","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/newlib@2.2.0+git20150830.5a3d536-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.0+git20141201.db59ff3-2","2.2.0+git20150830.5a3d536-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnewlib-arm-none-eabi","binary_version":"2.2.0+git20150830.5a3d536-1"},{"binary_name":"newlib-source","binary_version":"2.2.0+git20150830.5a3d536-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3420.json"}},{"package":{"name":"newlib","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/newlib@2.4.0.20160527-3ubuntu0.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.0.20160527-2","2.4.0.20160527-3","2.4.0.20160527-3ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnewlib-arm-none-eabi","binary_version":"2.4.0.20160527-3ubuntu0.1"},{"binary_name":"newlib-source","binary_version":"2.4.0.20160527-3ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3420.json"}},{"package":{"name":"newlib","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/newlib@3.3.0-0ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.0.20181231-1","3.3.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnewlib-arm-none-eabi","binary_version":"3.3.0-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3420.json"}},{"package":{"name":"newlib","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/newlib@3.3.0-1.3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.3.0-1","3.3.0-1.2","3.3.0-1.3"],"ecosystem_specific":{"binaries":[{"binary_name":"libnewlib-arm-none-eabi","binary_version":"3.3.0-1.3"},{"binary_name":"newlib-source","binary_version":"3.3.0-1.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3420.json"}},{"package":{"name":"newlib","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/newlib@4.4.0.20231231-2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.3.0-1.3","4.4.0.20231231-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libnewlib-arm-none-eabi","binary_version":"4.4.0.20231231-2"},{"binary_name":"newlib-source","binary_version":"4.4.0.20231231-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3420.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}