AI description
CVE-2024-57255 identifies an integer overflow vulnerability within the `sqfs_resolve_symlink` function in Das U-Boot (an open-source primary bootloader). Versions of Das U-Boot prior to 2025.01-rc1 are affected. This vulnerability occurs during the handling of symbolic links within SquashFS, a compressed read-only filesystem commonly used in embedded systems. The integer overflow stems from improper calculations when resolving symbolic links. While technical specifics and exploits aren't currently public, the vulnerability is considered easy to exploit and requires local access. Upgrading to Das U-Boot version 2025.01-rc1 or later mitigates this vulnerability. Note that this information is current as of February 19, 2025, and may change as more details become available.
- Description
- An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
- Source
- cve@mitre.org
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 7.1
- Impact score
- 6
- Exploitability score
- 0.5
- Vector string
- CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- HIGH
- cve@mitre.org
- CWE-190
- Hype score
- Not currently trending
CVE-2024-57255 An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a… https://t.co/mAlfVr0EWc
@CVEnew
18 Feb 2025
472 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
New post from https://t.co/uXvPWJy6tj (CVE-2024-57255 | DENEX U-Boot prior 2025.01-rc1 SquashFS Symlink Resolution integer overflow) has been published on https://t.co/548EjOHf0s
@WolfgangSesin
18 Feb 2025
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
U-Boot vulnerabilities https://t.co/T90biu2d32 CVE-2024-57254: Integer overflow in SquashFS symlink size calculation function CVE-2024-57255: Integer overflow in SquashFS symlink resolution function CVE-2024-57256: Integer overflow in ext4 symlink resolution function + next tweet
@oss_security
17 Feb 2025
2805 Impressions
6 Retweets
20 Likes
11 Bookmarks
1 Reply
0 Quotes