View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2024-57258 severity moderate: SUSE including 97 source package names (u-boot-avnetultra96rev1-2021.10-150600.11.3.1, u-boot-avnetultra96rev1-doc-2021.10-150600.11.3.1, …), 187 product×package rows across 11 product lines (SUSE Linux Enterprise Micro 5.2, SUSE Linux Enterprise Micro 5.3, … (11 product lines)): Fixed 187.
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.