Das U-Boot
cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*
- <= 2024.10
A heap memory corruption vulnerability has been identified in Das U-Boot versions prior to 2025.01-rc1. This issue arises in the 'sqfs_search_dir' function, which handles SquashFS directory listings. The vulnerability is caused by an off-by-one error that leads to improper size calculations, as the path separator is not adequately considered. An attacker capable of modifying SquashFS filesystem data structures can exploit this vulnerability.
Exploitation of this vulnerability leads to heap memory corruption, which can be manipulated to execute arbitrary code.
Users are advised to upgrade to U-Boot version 2025.01-rc1 or newer.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.