CVE-2024-57258

Published Feb 18, 2025

Last updated 9 days ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-57258 refers to integer overflow vulnerabilities within the memory allocation function of Das U-Boot (Universal Boot Loader) discovered in versions prior to 2025.01. These vulnerabilities affect the squashfs filesystem, specifically on x86_64 systems. Das U-Boot is a widely used open-source boot loader for embedded systems, enabling these systems to load and execute operating systems. The integer overflows occur during memory allocation, potentially leading to unexpected behavior or system crashes.

Description
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.
Source
cve@mitre.org
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.1
Impact score
6
Exploitability score
0.5
Vector string
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve@mitre.org
CWE-190

Social media

Hype score
Not currently trending