CVE-2024-10239: fld->used_bytes without sanity check causes stack overflow
A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which can cause a stack overflow due to the unchecked fat->fsd.maxfld.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10239?
The severity of CVE-2024-10239 is considered high due to its potential to allow an attacker with administrator privileges to cause a stack overflow.
How do I fix CVE-2024-10239?
To fix CVE-2024-10239, ensure you update the firmware for the Supermicro MBD-X12DPG-OA6 to the latest version provided by the vendor.
What are the potential impacts of CVE-2024-10239?
CVE-2024-10239 could lead to system instability or unauthorized code execution if an attacker exploits the stack overflow vulnerability.
Who is affected by CVE-2024-10239?
CVE-2024-10239 affects users of the Supermicro MBD-X12DPG-OA6 motherboard who have administrator access.
Is there a workaround for CVE-2024-10239?
Currently, there are no documented workarounds for CVE-2024-10239; firmware updates are recommended for mitigation.