# Silicon Labs Security Advisory A-00000279 : Update to “BadAlloc” Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations Flags: MCU CVSS Severity: Medium CVSS Base Score: 6.5, medium CVSS Temporal Score: 5.7, medium CVSS String: [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C) ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | Micrium OS | 5.10.1 and earlier | - | - | [CVE-2021-26706](https://nvd.nist.gov/vuln/detail/CVE-2021-26706) | ### Source Product Impact Details This is an update to security advisory A-00000177, which is appended at the end this advisory for reference, to make the following adjustments to that advisory: - CVSS Base Score, Temporal Score, and Vector String have been updated due to correcting the Attack Complexity from "Low" to "High" and the “Availability Impact” from “Low” to “High”. The overall CVSS score of 5.7 and CVSS Severity of "Medium" remain unchanged. - The corrected version of uC/LIB is 1.39.1. The previous advisory stated that the corrected version was 1.39.01. - The addition of the ‘BadAlloc’ name to the advisory subject - Added links to the CISA advisory about this issue and to CWE-190. - User applications built on Micrium OS version 5.10.1 or earlier which make direct calls to Mem_DynPoolCreate, Mem_DynPoolCreateHW or Mem_PoolCreate may be impacted. All Micrium OS and uC/OS-II and uC/OS-III products as delivered use safe compile-time constants for memory allocation and are not impacted. - User applications built on uC/OS-II and uC/OS-III using uC/LIB version 1.39.00 or earlier which make direct calls to Mem_DynPoolCreate, Mem_DynPoolCreateHW or Mem_PoolCreate may be impacted. All Micrium OS and uC/OS-II and uC/OS-III products as delivered use safe compile-time constants for memory allocation and are not impacted. ## Description - [CVE-2021-26706](https://nvd.nist.gov/vuln/detail/CVE-2021-26706) has been reserved for this issue. - The Cybersecurity and Infrastructure Agency (CISA) has issued advisory [ICSA-21-119-04](https://us-cert.cisa.gov/ics/advisories/icsa-21-119-04) about these issues. - Additional information about this vulnerability is available at [CWE-190](https://cwe.mitre.org/data/definitions/190.html). - Three memory allocation functions perform potentially unsafe size calculations which could lead to an integer overflow and hence a very small block of memory being allocated. - The affected functions are Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate (deprecated). - All Micrium OS and uC/OS-II and uC/OS-III products as delivered use safe compile-time constants for memory allocation; user application code making direct calls to the affected functions may still be impacted. - User application code should take care to validate parameters before passing them to the affected functions. ### Fix/Workaround - A work-around for this issue in user application code is to ensure that the requested memory size does not exceed the limit of a 32-bit integer in calls to Mem_DynPoolCreate, Mem_DynPoolCreateHW or Mem_PoolCreate. - This has been fixed in Micrium OS to version 5.10.2 and later. EFR32/EFM32 applications using Micrium OS should upgrade once the fix becomes available using Simplicity Studio v5’s help -> Update Software -> Manage installed packages -> SDKs -> Micrium OS and click the Install button. - This has been fixed in uC/LIB, which is used by uC/OS-II and uC/OS-III, version 1.39.01 and later and can be found [here](https://github.com/weston-embedded/uC-LIB). uCOS-II and uCOS-III products are now supported by [Weston Embedded](https://weston-embedded.com/) they are available help. Subject: Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations ## Product Impact - User applications built on Micrium OS version 5.10.1 or earlier which make direct calls to Mem_DynPoolCreate, Mem_DynPoolCreateHW or Mem_PoolCreate may be impacted. All Micrium OS and uC/OS-II and uC/OS-III products as delivered use safe compile-time constants for memory allocation and are not impacted. - User applications built on uC/OS-II and uC/OS-III using uC/LIB version 1.39.00 or earlier which make direct calls to Mem_DynPoolCreate, Mem_DynPoolCreateHW or Mem_PoolCreate may be impacted. All Micrium OS and uC/OS-II and uC/OS-III products as delivered use safe compile-time constants for memory allocation and are not impacted. ## Description - [CVE-2021-26706](https://nvd.nist.gov/vuln/detail/CVE-2021-26706) has been reserved for this issue - Three memory allocation functions perform potentially unsafe size calculations which could lead to an integer overflow and hence a very small block of memory being allocated. - The affected functions are Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate (deprecated). ## Attribution ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 1.0 | 2021-JUN-01 | Initial publication | ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)