Vulnerability Description
In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related issue to CVE-2024-57256.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://git.pengutronix.de/cgit/barebox/commit/?id=a2b76550f7d8
- https://git.pengutronix.de/cgit/barebox/commit/?id=a2b76550f7d87ba6f88a9ea50e71f
FAQ
What is CVE-2024-57262?
CVE-2024-57262 is a vulnerability with a CVSS score of 7.1 (HIGH). In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a mall...
How severe is CVE-2024-57262?
CVE-2024-57262 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57262?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.