The Gumstix Overo SBC on the VSKS board through 2022-08-09, as used on the Orlan-10 and other platforms, allows unrestricted remapping of the NOR flash memory containing the bitstream for the FPGA.
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Link | Tags |
---|---|
https://github.com/subreption/birdwatch-report-1-repo | third party advisory |
https://subreption.com/downloads/reports/demystifying-the-orlan-10_opt.pdf | third party advisory technical description |
https://subreption.com/press-releases/2022-birdwatch-first-report/ | third party advisory |