Overview
What is CVE-2024-57255?
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
Vulnerability intelligence
CVE-2024-57255 and is rated Medium severity with a CVSS score of 6.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.