Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.
Metrics
Affected Vendors & Products
References
History
Thu, 22 Aug 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Renesas
Renesas arm-trusted-firmware |
|
CPEs | cpe:2.3:o:renesas:arm-trusted-firmware:-:*:*:*:*:*:*:* | |
Vendors & Products |
Rensas
Rensas arm-trusted-firmware |
Renesas
Renesas arm-trusted-firmware |
MITRE
Status: PUBLISHED
Assigner: ASRG
Published: 2024-07-08T15:18:17.265Z
Updated: 2024-08-01T21:41:03.762Z
Reserved: 2024-07-08T15:06:44.987Z
Link: CVE-2024-6564
Vulnrichment
Updated: 2024-08-01T21:41:03.762Z
NVD
Status : Modified
Published: 2024-07-08T16:15:09.423
Modified: 2024-11-21T09:49:53.680
Link: CVE-2024-6564
Redhat
No data.