Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openamp
Openamp openamp |
|
| Vendors & Products |
Openamp
Openamp openamp |
Sat, 02 May 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Overflow in OpenAMP ELF Loader on 32‑Bit Embedded Systems |
Fri, 01 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 |
Fri, 01 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit values from the ELF header without overflow checking. On 32-bit embedded systems (STM32MP1, Zynq, i.MX), large values can cause the product to wrap around to a small value. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-01T17:44:59.342Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37540
Updated: 2026-05-01T17:44:55.336Z
Status : Awaiting Analysis
Published: 2026-05-01T17:16:23.933
Modified: 2026-05-07T15:53:49.717
Link: CVE-2026-37540
No data.
OpenCVE Enrichment
Updated: 2026-05-04T16:11:43Z