CVE-2024-1633
19.02.2024, 17:15
During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table bl2_mem_params_descs. For each image, the bl2 reads the image length and destination from the images certificate.Because of the way of reading from the image, which base on32-bit unsigned integer value, it can result toan integer overflow.An attacker can bypass memory range restriction and write data out of buffer bounds, which could result in bypass of secure boot. Affected git version fromc2f286820471ed276c57e603762bd831873e5a17 until (notEnginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.