CVE-2021-22156 - CVE House
Back to Database
Status published Critical CVE-2021-22156

An integer overflow vulnerability in the calloc() function of the...

Vulnerability Description

An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-22156

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

QNX Software Development Platform (SDP), QNX OS for Medical and QNX OS for Safety
Vulnerable Versions:
QNX SDP 6.5.0 SP1 and earlier, QNX OS for Medical 1.1 and earlier, QNX OS for Safety 1.0.1 and earlier

Timeline

Official Publish: August 17th, 2021
Last Modified: August 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)