First published: Tue Feb 18 2025(Updated: )
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Das U-Boot | <2025.01-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57255 is classified as a high-severity vulnerability due to its potential for memory overwrite exploitation.
To mitigate CVE-2024-57255, update Das U-Boot to version 2025.01-rc1 or later.
CVE-2024-57255 affects versions of Das U-Boot prior to 2025.01-rc1 that utilize a crafted squashfs filesystem.
CVE-2024-57255 can be exploited through crafted squashfs filesystems that trigger memory overwrite due to an integer overflow.
Currently, the best practice is to avoid using untrusted or crafted squashfs filesystems until a proper update is applied.