CVE-2025-24857: High severity DENX Universal Boot Loader (U-Boot) vulnerability
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24857?
CVE-2025-24857 is considered a critical vulnerability due to its potential to allow unauthorized execution of arbitrary code.
How do I fix CVE-2025-24857?
To mitigate CVE-2025-24857, update the Universal Boot Loader (U-Boot) to version 2017.11 or later.
What products are affected by CVE-2025-24857?
CVE-2025-24857 affects Denx Universal Boot Loader versions prior to 2017.11 and multiple Qualcomm chips, including IPQ4019 and IPQ8074.
Can CVE-2025-24857 be exploited remotely?
Yes, an attacker could exploit CVE-2025-24857 remotely if they have access to the vulnerable device's memory.
What type of attack can CVE-2025-24857 enable?
CVE-2025-24857 can enable attackers to execute arbitrary code on vulnerable devices, leading to potential system compromise.