CVE-2024-57259: High severity das u-boot vulnerability
Published Feb 18, 2025
·Updated
sqfssearchdir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation.
Affected Software
2 affected components
Das U-Boot Das U-Boot<2025.01-rc1
DENX U-Boot<=2024.10
Remediation
Event History
Feb 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 22, 57721
Event
via MITRE·12:43 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-57259?
CVE-2024-57259 is classified as a high-severity vulnerability due to its potential for causing heap memory corruption.
2
How do I fix CVE-2024-57259?
To resolve CVE-2024-57259, upgrade Das U-Boot to version 2025.01-rc1 or later.
3
What causes CVE-2024-57259?
CVE-2024-57259 is caused by an off-by-one error in the sqfs_search_dir function that leads to heap memory corruption.
4
What systems are affected by CVE-2024-57259?
CVE-2024-57259 affects Das U-Boot versions prior to 2025.01-rc1.
5
What are the potential impacts of CVE-2024-57259?
The potential impacts of CVE-2024-57259 include arbitrary code execution and system instability due to memory corruption.