Integer Overflow Vulnerability in Barebox Affecting ext4 Filesystem
CVE-2024-57262

7.1HIGH

Key Information:

Vendor
Pengutronix
Status
Barebox
Vendor
CVE Published:
19 February 2025

Summary

In Barebox versions before 2025.01.0, an integer overflow occurs within the ext4fs_read_symlink function due to improper handling of inode sizes, specifically when the inode size is set to 0xffffffff. This vulnerability can be exploited through a specially crafted ext4 filesystem, potentially leading to a malloc of zero bytes and subsequent memory overwrite. The exploit correlates with similar issues documented in CVE-2024-57256, emphasizing the need for immediate attention to secure the affected versions.

Affected Version(s)

barebox 0 < 2025.01.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.