TencentOS-tiny version 3.1.0 is vulnerable to integer...
Critical severity
Unreviewed
Published
May 4, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 3, 2022
Published to the GitHub Advisory Database
May 4, 2022
Last updated
Feb 1, 2023
TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
References