CVE-2020-28895: Oracle Communications Eagle

High severity, CVSS 7.3. EPSS: 1.6% chance of exploitation in the next 30 days.

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

Affected products

  • Oracle Communications Eagle: from 46.8.0, up to and including 48.6.2; from 46.9.1, up to and including 46.9.3; version 46.7.0 only
  • Windriver Vxworks: from 6.9, before 6.9.4.12 (fixed in 6.9.4.12); version 6.9.4.12 only

Published 2021-02-03. Last modified 2026-06-17.