CVE-2024-6564: Renesas Arm-Trusted-Firmware

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.

Affected products

  • Renesas Arm-Trusted-Firmware: affected versions not specified

Published 2024-07-08. Last modified 2026-06-17.