Integer Overflow to Buffer Overflow
CVE-2023-28585
Summary
Memory corruption while loading an ELF segment in TEE Kernel.
- LOW
- LOCAL
- HIGH
- CHANGED
- NONE
- HIGH
- HIGH
- HIGH
CWE-680 - Integer Overflow to Buffer Overflow
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
References
Advisory Timeline
- Published