High severity7.1NVD Advisory· Published Feb 18, 2025· Updated May 12, 2026
CVE-2024-57258
CVE-2024-57258
Description
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
53- osv-coords50 versionspkg:rpm/opensuse/u-boot-avnetultra96rev1&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-bananapim64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-dragonboard410c&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-dragonboard820c&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-evb-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-firefly-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-geekbox&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-hikey&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-khadas-vim2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-khadas-vim&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-libretech-ac&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-libretech-cc&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-ls1012afrdmqspi&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebudb-88f3720&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebudbarmada8k&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebuespressobin-88f3720&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-mvebumcbin-88f8040&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-nanopia64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-odroid-c2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-odroid-c4&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-odroid-n2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-orangepipc2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-p2371-2180&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-p2771-0000-500&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-p3450-0000&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pine64plus&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pinebook&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pinebook-pro-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pineh64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-pinephone&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-poplar&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock64-rk3328&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock960-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock-pi-4-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rock-pi-n10-rk3399pro&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rockpro64-rk3399&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rpi3&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rpi4&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-rpiarm64&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-xilinxzynqmpgeneric&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-xilinxzynqmpvirt&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/u-boot-xilinxzynqmpzcu102rev10&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/u-boot&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Micro%206.0
< 2021.10-150600.11.3.1+ 49 more
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2020.01-150200.10.18.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2021.01-150300.7.24.1
- (no CPE)range: < 2021.10-150400.4.14.1
- (no CPE)range: < 2021.10-150400.4.14.1
- (no CPE)range: < 2021.10-150400.4.14.1
- (no CPE)range: < 2021.10-150600.11.3.1
- (no CPE)range: < 2023.04-2.1
Patches
Vulnerability mechanics
References
6- source.denx.de/u-boot/u-boot/-/commit/0a10b49206a29b4aa2f80233a3e53ca0466bb0b3nvdPatch
- source.denx.de/u-boot/u-boot/-/commit/8642b2178d2c4002c99a0b69a845a48f2ae2706fnvdPatch
- source.denx.de/u-boot/u-boot/-/commit/c17b2a05dd50a3ba437e6373093a0d6a359cdee0nvdPatch
- www.openwall.com/lists/oss-security/2025/02/17/2nvdMailing ListMitigationThird Party Advisory
- cert-portal.siemens.com/productcert/html/ssa-577017.htmlnvd
- lists.debian.org/debian-lts-announce/2025/05/msg00001.htmlnvd
News mentions
1- Siemens Ruggedcom RoxCISA ICS Advisories