Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code.
When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite an already loaded image partly or completely, which could result in code execution and bypass of secure boot.
References
Link | Resource |
---|---|
https://asrg.io/security-advisories/cve-2024-6287/ | Third Party Advisory |
https://github.com/renesas-rcar/arm-trusted-firmware/commit/954d488a9798f8fda675c6b57c571b469b298f04 | Patch |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ASRG
Published: 2024-06-24T15:37:15.953Z
Updated: 2024-07-04T14:43:09.532Z
Reserved: 2024-06-24T15:32:45.202Z
Link: CVE-2024-6287
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-06-24T16:15:11.003
Modified: 2024-06-26T14:36:08.507
Link: CVE-2024-6287
JSON object: View
Redhat Information
No data.
CWE