PT-2025-6747 · Barebox · Barebox

Ahmad Fatoum

+1

·

Published

2025-02-17

·

Updated

2025-02-24

·

CVE-2024-57261

CVSS v3.1

7.1

High

VectorAV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions barebox versions prior to 2025.01.0
Description The issue is related to an integer overflow in the request2size function in common/dlmalloc.c.
Recommendations For versions prior to 2025.01.0, update to version 2025.01.0 or later to resolve the issue.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-57261

Affected Products

Barebox