CVE-2024-57254: Integer Overflow
Published Feb 18, 2025
·Updated
An integer overflow in sqfsinodesize in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem.
Affected Software
2 affected components
Das U-Boot Das U-Boot<2025.01-rc1
DENX U-Boot<=2024.10
Remediation
Event History
Feb 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57254?
The severity of CVE-2024-57254 is considered critical due to the potential for exploitation via a crafted squashfs filesystem.
2
How do I fix CVE-2024-57254?
To fix CVE-2024-57254, update Das U-Boot to version 2025.01-rc1 or later.
3
What software is affected by CVE-2024-57254?
CVE-2024-57254 affects Das U-Boot versions prior to 2025.01-rc1.
4
What type of vulnerability is CVE-2024-57254?
CVE-2024-57254 is an integer overflow vulnerability affecting the symlink size calculation.
5
Can CVE-2024-57254 lead to system compromise?
Yes, CVE-2024-57254 can potentially lead to system compromise if exploited through a specially crafted squashfs filesystem.