CVE-2024-57257: Low severity das u-boot vulnerability
Published Feb 18, 2025
·Updated
A stack consumption issue in sqfssize in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.
Affected Software
2 affected components
Das U-Boot Das U-Boot<2025.01-rc1
DENX U-Boot<=2024.10
Remediation
Event History
Feb 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57257?
CVE-2024-57257 has a high severity due to its potential for causing stack consumption through crafted squashfs filesystems.
2
How do I fix CVE-2024-57257?
To fix CVE-2024-57257, you should update Das U-Boot to version 2025.01-rc1 or later.
3
What causes CVE-2024-57257?
CVE-2024-57257 is caused by a stack consumption issue in the sqfs_size function due to deep symlink nesting in squashfs filesystems.
4
Which versions of Das U-Boot are affected by CVE-2024-57257?
CVE-2024-57257 affects all versions of Das U-Boot prior to 2025.01-rc1.
5
Can CVE-2024-57257 be exploited remotely?
CVE-2024-57257 can potentially be exploited remotely if an attacker can present a crafted squashfs filesystem to a vulnerable instance of Das U-Boot.