This package includes the mkimage program, which allows generation of U-Boot images in various formats, and the fwprintenv and fwsetenv programs to read and modify U-Boot's environment.
Security Fix(es):
An integer overflow in ext4fsreadsymlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.(CVE-2024-57256)
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdifft is mishandled on x8664.(CVE-2024-57258)
{ "severity": "High" }
{ "noarch": [ "uboot-images-armv8-2020.07-9.oe2003sp4.noarch.rpm", "uboot-tools-help-2020.07-9.oe2003sp4.noarch.rpm" ], "src": [ "uboot-tools-2020.07-9.oe2003sp4.src.rpm" ], "aarch64": [ "uboot-images-elf-2020.07-9.oe2003sp4.aarch64.rpm", "uboot-tools-2020.07-9.oe2003sp4.aarch64.rpm", "uboot-tools-debuginfo-2020.07-9.oe2003sp4.aarch64.rpm", "uboot-tools-debugsource-2020.07-9.oe2003sp4.aarch64.rpm" ], "x86_64": [ "uboot-tools-2020.07-9.oe2003sp4.x86_64.rpm", "uboot-tools-debuginfo-2020.07-9.oe2003sp4.x86_64.rpm", "uboot-tools-debugsource-2020.07-9.oe2003sp4.x86_64.rpm" ] }