Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware.
An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.
References
Link | Resource |
---|---|
https://asrg.io/security-advisories/cve-2024-6285/ | Third Party Advisory |
https://github.com/renesas-rcar/arm-trusted-firmware/commit/b596f580637bae919b0ac3a5471422a1f756db3b | Patch |
Configurations
History
26 Jun 2024, 14:24
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
References | () https://asrg.io/security-advisories/cve-2024-6285/ - Third Party Advisory | |
References | () https://github.com/renesas-rcar/arm-trusted-firmware/commit/b596f580637bae919b0ac3a5471422a1f756db3b - Patch | |
CPE | cpe:2.3:a:renesas:rcar_gen3:v2.5:*:*:*:*:*:*:* | |
First Time |
Renesas rcar Gen3
Renesas |
|
Summary |
|
24 Jun 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-24 16:15
Updated : 2024-06-26 14:24
NVD link : CVE-2024-6285
Mitre link : CVE-2024-6285
CVE.ORG link : CVE-2024-6285
JSON object : View
Products Affected
renesas
- rcar_gen3
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)