Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
{
"cpe": "cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "10.1.0"
}
]
}
[
{
"id": "CVE-2021-26461-60c2ac9e",
"target": {
"file": "arch/risc-v/src/k210/k210_irq.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"316238073908397001294668170111245935112",
"243780462924448801141492148254774031381",
"276030682232053770831914696041104985276",
"119304014593459627961731653517724272458"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/nuttx/commit/3130ff691e386934eb276587a24d1efacf3bb30b",
"signature_type": "Line"
},
{
"id": "CVE-2021-26461-df5bd412",
"target": {
"function": "up_irqinitialize",
"file": "arch/risc-v/src/k210/k210_irq.c"
},
"deprecated": false,
"digest": {
"function_hash": "105513224271813551519762554760106111115",
"length": 932.0
},
"signature_version": "v1",
"source": "https://github.com/apache/nuttx/commit/3130ff691e386934eb276587a24d1efacf3bb30b",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26461.json"
"2026-07-09T06:02:07Z"