Das U-Boot Heap Corruption Vulnerability in SquashFS Directory Listing

Vulnerability

A heap memory corruption vulnerability has been identified in Das U-Boot versions prior to 2025.01-rc1. This issue arises in the 'sqfs_search_dir' function, which handles SquashFS directory listings. The vulnerability is caused by an off-by-one error that leads to improper size calculations, as the path separator is not adequately considered. An attacker capable of modifying SquashFS filesystem data structures can exploit this vulnerability.

Impact

Exploitation of this vulnerability leads to heap memory corruption, which can be manipulated to execute arbitrary code.

Remediation

Users are advised to upgrade to U-Boot version 2025.01-rc1 or newer.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
7.5
exploitability
4.0
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.