Incorrect calculation in arm-trusted-firmware - CVE-2024-6287
Published: December 20, 2024
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect calculation. When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. A local user can bypass secure boot restrictions and escalate privileges on the system.
Affected software
openEuler
arm-trusted-firmware
arm-trusted-firmware-armv8
How to mitigate CVE-2024-6287
arm-trusted-firmware-armv8 - addressed in versions 2.3-6, 2.9-4