CVE-2024-25076

An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function responsible for validating the Flash Product Header directly uses a user-controllable size value (Length of Flash Config Section) to control a read from the QSPI device into a fixed sized buffer, resulting in a buffer overflow and execution of arbitrary code.
Configurations

No configuration.

History

No history.

Information

Published : 2024-07-10 20:15

Updated : 2024-11-21 09:00


NVD link : CVE-2024-25076

Mitre link : CVE-2024-25076

CVE.ORG link : CVE-2024-25076


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')