High severity7.1NVD Advisory· Published Feb 18, 2025· Updated Jun 17, 2026
CVE-2024-57255
CVE-2024-57255
Description
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- source.denx.de/u-boot/u-boot/-/commit/233945eba63e24061dffeeaeb7cd6fe985278356nvdPatch
- www.openwall.com/lists/oss-security/2025/02/17/2nvdMailing ListMitigationThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/05/msg00001.htmlnvd
News mentions
0No linked articles in our index yet.