# CVE-2024-57259

## Summary

- **CVE ID:** CVE-2024-57259
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-193
- **Published:** Feb 18, 2025
- **Last Modified:** Mar 13, 2026

## Description

sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation.

## Affected Products

- denx — U-Boot (0)

## References

- [CNA](https://source.denx.de/u-boot/u-boot/-/commit/048d795bb5b3d9c5701b4855f5e74bcf6849bf5e)
- [CNA](https://www.openwall.com/lists/oss-security/2025/02/17/2)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/05/msg00001.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.36%
- **EPSS Percentile:** 29.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._