Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code.
When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite an already loaded image partly or completely, which could result in code execution and bypass of secure boot.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ASRG
Published: 2024-06-24T15:37:15.953Z
Updated: 2024-08-01T21:33:05.333Z
Reserved: 2024-06-24T15:32:45.202Z
Link: CVE-2024-6287
Vulnrichment
Updated: 2024-08-01T21:33:05.333Z
NVD
Status : Modified
Published: 2024-06-24T16:15:11.003
Modified: 2024-11-21T09:49:21.517
Link: CVE-2024-6287
Redhat
No data.