#VU120245 Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) - CVE-2025-24857
Published: December 23, 2025
Universal Boot Loader (U-Boot)
DENX
Description
The vulnerability allows an attacker to compromise the affected system.
The vulnerability exists due to an improper access control in the bootloader. An attacker with physical proximity to the system can execute arbitrary code.
The vulnerability affects systems on Qualcomm chips: IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574.