PT-2024-37513 · Renesas+1 · Arm Trusted Firmware+1

Tomer Fichman

·

Published

2024-06-24

·

Updated

2024-12-20

·

CVE-2024-6285

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Renesas arm-trusted-firmware (affected versions not specified)
Description: The issue is related to an integer underflow in image range check calculations, which could allow bypassing address restrictions and loading images to unallowed addresses. This could potentially lead to security breaches by loading malicious images.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2024-6285
OESA-2024-2565
OESA-2024-2566
OESA-2024-2567
OESA-2024-2568

Affected Products

Debian
Arm Trusted Firmware