CVE-2024-57259
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-57259 is a newly disclosed vulnerability affecting Das U-Boot versions prior to 2025.01-rc1. This issue stems from an off-by-one error in the sqfs_search_dir function, which causes heap memory corruption during squashfs directory listings. The error occurs because the path separator character is not taken into account when calculating size, leading to inaccurate size calculations and subsequent memory corruption. This vulnerability may potentially be exploited by attackers to execute arbitrary code or cause denial-of-service conditions. Users are strongly urged to update their Das U-Boot installations to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.