Integer Overflow Vulnerability in Barebox Affecting ext4 Filesystem
CVE-2024-57262
7.1HIGH
Key Information:
- Vendor
- Pengutronix
- Status
- Barebox
- Vendor
- CVE Published:
- 19 February 2025
Summary
In Barebox versions before 2025.01.0, an integer overflow occurs within the ext4fs_read_symlink function due to improper handling of inode sizes, specifically when the inode size is set to 0xffffffff. This vulnerability can be exploited through a specially crafted ext4 filesystem, potentially leading to a malloc of zero bytes and subsequent memory overwrite. The exploit correlates with similar issues documented in CVE-2024-57256, emphasizing the need for immediate attention to secure the affected versions.
Affected Version(s)
barebox 0 < 2025.01.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved