Das U-Boot
cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*
- <= 2024.10
A vulnerability exists in Das U-Boot bootloader versions prior to 2025.01-rc1, due to an integer overflow in the 'sqfs_resolve_symlink' function. This vulnerability can be triggered by a crafted SquashFS filesystem that includes an inode size of 0xffffffff. The resulting memory corruption occurs because the overflow leads to a memory allocation of zero, which is then overwritten, creating potential for exploitation.
Exploitation of this vulnerability causes memory corruption, which can be leveraged to bypass verified boot processes, disrupt the chain of trust, and execute arbitrary code.
Users are advised to upgrade to U-Boot version 2025.01-rc1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.