High severity7.1NVD Advisory· Published Feb 18, 2025· Updated May 12, 2026
CVE-2024-57256
CVE-2024-57256
Description
An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
53- osv-coords50 versionspkg:rpm/opensuse/u-boot-avnetultra96rev1&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-bananapim64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-dragonboard410c&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-dragonboard820c&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-evb-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-firefly-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-geekbox&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-hikey&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-khadas-vim2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-khadas-vim&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-libretech-ac&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-libretech-cc&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-ls1012afrdmqspi&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebudb-88f3720&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebudbarmada8k&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebuespressobin-88f3720&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebumcbin-88f8040&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-nanopia64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-odroid-c2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-odroid-c4&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-odroid-n2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-orangepipc2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-p2371-2180&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-p2771-0000-500&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-p3450-0000&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pine64plus&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pinebook&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pinebook-pro-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pineh64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pinephone&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-poplar&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock64-rk3328&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock960-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock-pi-4-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock-pi-n10-rk3399pro&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rockpro64-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rpi3&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rpi4&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rpiarm64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-xilinxzynqmpgeneric&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-xilinxzynqmpvirt&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-xilinxzynqmpzcu102rev10&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/u-boot&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Micro%206.0
< 2021.10-150600.11.3.1+ 49 more
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2020.01-150200.10.18.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.01-150300.7.24.1
- (no CPE)range: < 2021.10-150400.4.14.1
- (no CPE)range: < 2021.10-150400.4.14.1
- (no CPE)range: < 2021.10-150400.4.14.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2023.04-2.1
Patches
Vulnerability mechanics
References
4News mentions
1- Siemens Ruggedcom RoxCISA ICS Advisories