Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6564

Опубликовано: 08 июл. 2024
Источник: debian

Описание

Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
arm-trusted-firmwarefixed2.12.0+dfsg-1experimentalpackage
arm-trusted-firmwarefixed2.12.0+dfsg-2package
arm-trusted-firmwareno-dsabookwormpackage
arm-trusted-firmwareno-dsabullseyepackage

Примечания

  • https://github.com/renesas-rcar/arm-trusted-firmware/commit/c9fb3558410032d2660c7f3b7d4b87dec09fe2f2

  • https://asrg.io/security-advisories/cve-2024-6564/

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 1 года назад

Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.

CVSS3: 6.7
nvd
больше 1 года назад

Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.

CVSS3: 6.7
github
больше 1 года назад

Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.