#VU101887 Incorrect calculation in arm-trusted-firmware - CVE-2024-6287
Published: December 20, 2024
arm-trusted-firmware
renesas-rcar
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect calculation. When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. A local user can bypass secure boot restrictions and escalate privileges on the system.