CVE-2020-35198: Oracle Communications Eagle

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

Affected products

  • Oracle Communications Eagle: from 46.8.0, up to and including 46.8.2; from 46.9.1, up to and including 46.9.3; version 46.7.0 only
  • Windriver Vxworks: from 6.9, before 6.9.4.12 (fixed in 6.9.4.12); from 7.0, before 21.03 (fixed in 21.03); version 6.9.4.12 only

Published 2021-05-12. Last modified 2026-06-17.