Vulnerabilities (CVE)

Filtered by vendor Denx Subscribe
Filtered by product U-boot
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-33103 1 Denx 1 U-boot 2022-07-15 4.6 MEDIUM 7.8 HIGH
Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
CVE-2022-30790 1 Denx 1 U-boot 2022-06-16 7.2 HIGH 7.8 HIGH
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
CVE-2019-13104 1 Denx 1 U-boot 2021-07-21 6.8 MEDIUM 7.8 HIGH
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
CVE-2020-10648 2 Denx, Opensuse 2 U-boot, Leap 2021-03-26 6.8 MEDIUM 7.8 HIGH
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
CVE-2021-27138 1 Denx 1 U-boot 2021-02-24 6.8 MEDIUM 7.8 HIGH
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
CVE-2021-27097 1 Denx 1 U-boot 2021-02-23 6.8 MEDIUM 7.8 HIGH
The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
CVE-2019-13103 1 Denx 1 U-boot 2020-08-24 3.6 LOW 7.1 HIGH
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.
CVE-2018-18440 1 Denx 1 U-boot 2019-12-10 7.2 HIGH 7.8 HIGH
DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.
CVE-2019-13106 1 Denx 1 U-boot 2019-10-01 8.3 HIGH 7.8 HIGH
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
CVE-2019-13105 1 Denx 1 U-boot 2019-08-13 6.8 MEDIUM 7.8 HIGH
Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
CVE-2018-3968 1 Denx 1 U-boot 2019-04-02 4.4 MEDIUM 7.0 HIGH
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.