RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in…
中危 CVSS 5.3
摘要
RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only the first few bytes of the payload. Given such a bundle with a legitimate signature, an attacker can modify the part of the payload which is not covered by the signature. This issue has been patched in version 1.15.2.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/rauc/rauc/commit/4fb7c798d6ae412344fb8f8d310d773046af3441 Patch
- https://github.com/rauc/rauc/releases/tag/v1.15.2 Release Notes
- https://github.com/rauc/rauc/security/advisories/GHSA-6hj7-q844-m2hx Mitigation
时间线
- nvd_ingest NVD