Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.
[
{
"id": "CVE-2024-6285-d6e96990",
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "drivers/renesas/common/io/io_rcar.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"167545474265535815709469781345846274975",
"83672508553065906885160285310470229070",
"192449489686858836217356063237994548850",
"44563517852321594524543286850430926918",
"107636787740302120215243284208098469223",
"244833072605430231046001163781989143690",
"58933159413703032944791521093473852621",
"286653017787239719823438752341224643558"
],
"threshold": 0.9
},
"source": "https://github.com/renesas-rcar/arm-trusted-firmware/commit/b596f580637bae919b0ac3a5471422a1f756db3b"
},
{
"id": "CVE-2024-6285-d9121ddb",
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "drivers/renesas/common/io/io_rcar.c",
"function": "check_load_area"
},
"deprecated": false,
"digest": {
"length": 881.0,
"function_hash": "117185750020082507362494084268299919491"
},
"source": "https://github.com/renesas-rcar/arm-trusted-firmware/commit/b596f580637bae919b0ac3a5471422a1f756db3b"
}
]