CVE-2024-57255
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Feb 18, 2025
Updated: Feb 19, 2025
CWE ID 190
Summary
CVE-2024-57255 is a newly disclosed vulnerability affecting Das U-Boot versions prior to 2025.01-rc1. The weakness stems from an integer overflow issue in the 'sqfs_resolve_symlink' function. This flaw can be exploited through a specially crafted squashfs filesystem with an inode size of 0xffffffff, leading to a malloc of zero and subsequent memory overwrite. This vulnerability could potentially result in arbitrary code execution or system crashes. It is recommended that users upgrade to the latest version of U-Boot to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share