First published: Tue Feb 18 2025(Updated: )
A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Das U-Boot | <2025.01-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57257 has a high severity due to its potential for causing stack consumption through crafted squashfs filesystems.
To fix CVE-2024-57257, you should update Das U-Boot to version 2025.01-rc1 or later.
CVE-2024-57257 is caused by a stack consumption issue in the sqfs_size function due to deep symlink nesting in squashfs filesystems.
CVE-2024-57257 affects all versions of Das U-Boot prior to 2025.01-rc1.
CVE-2024-57257 can potentially be exploited remotely if an attacker can present a crafted squashfs filesystem to a vulnerable instance of Das U-Boot.