CVE-2024-57255

Published Feb 18, 2025

Last updated 9 days ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-57255 identifies an integer overflow vulnerability within the `sqfs_resolve_symlink` function in Das U-Boot (an open-source primary bootloader). Versions of Das U-Boot prior to 2025.01-rc1 are affected. This vulnerability occurs during the handling of symbolic links within SquashFS, a compressed read-only filesystem commonly used in embedded systems. The integer overflow stems from improper calculations when resolving symbolic links. While technical specifics and exploits aren't currently public, the vulnerability is considered easy to exploit and requires local access. Upgrading to Das U-Boot version 2025.01-rc1 or later mitigates this vulnerability. Note that this information is current as of February 19, 2025, and may change as more details become available.

Description
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
Source
cve@mitre.org
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.1
Impact score
6
Exploitability score
0.5
Vector string
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve@mitre.org
CWE-190

Social media

Hype score
Not currently trending