Integer Overflow Vulnerability in Das U-Boot's ext4 Filesystem Handling
CVE-2024-57256
7.1HIGH
What is CVE-2024-57256?
This vulnerability arises from an integer overflow in the ext4fs_read_symlink function within Das U-Boot, specifically in versions prior to 2025.01-rc1. An attacker can exploit this flaw through a crafted ext4 filesystem that exploits the inode size, potentially leading to a malloc of zero and causing unsafe memory overwrites. If left unaddressed, this could allow for unauthorized memory manipulation, resulting in potential instability or compromise of system integrity.
Affected Version(s)
U-Boot 0 < 2025.01-rc1
