VYPR

arm-trusted-firmware

by Renesas Rcar

CVEs (2)

  • CVE-2024-6564MedJul 8, 2024
    risk 0.00cvss 6.7epss 0.00

    Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.

  • CVE-2024-6285HigJun 24, 2024
    risk 0.00cvss 7.5epss 0.00

    Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.