CVE-2024-6564: Renesas Arm-Trusted-Firmware
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.
Affected products
- Renesas Arm-Trusted-Firmware: affected versions not specified
Published 2024-07-08. Last modified 2026-06-17.