Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6285

Опубликовано: 24 июн. 2024
Источник: debian
EPSS Низкий

Описание

Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
arm-trusted-firmwarefixed2.12.0+dfsg-1experimentalpackage
arm-trusted-firmwareunfixedpackage

Примечания

  • https://github.com/renesas-rcar/arm-trusted-firmware/commit/b596f580637bae919b0ac3a5471422a1f756db3b

  • https://asrg.io/security-advisories/cve-2024-6285-integer-underflow-in-memory-range-check-in-renesas-rcar/

  • Vulnerable targets not built in Debian

EPSS

Процентиль: 1%
0.00008
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.

CVSS3: 7.5
nvd
больше 1 года назад

Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.

CVSS3: 7.5
github
больше 1 года назад

Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.

EPSS

Процентиль: 1%
0.00008
Низкий