CVE-2024-57259

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 19, 2025
CWE ID 193

Summary

CVE-2024-57259 is a newly disclosed vulnerability affecting Das U-Boot versions prior to 2025.01-rc1. This issue stems from an off-by-one error in the sqfs_search_dir function, which causes heap memory corruption during squashfs directory listings. The error occurs because the path separator character is not taken into account when calculating size, leading to inaccurate size calculations and subsequent memory corruption. This vulnerability may potentially be exploited by attackers to execute arbitrary code or cause denial-of-service conditions. Users are strongly urged to update their Das U-Boot installations to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share