Medium severity6.2NVD Advisory· Published May 11, 2026· Updated May 13, 2026
CVE-2026-34961
CVE-2026-34961
Description
barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.c. Attackers can supply a malicious ext4 filesystem image via USB, SD card, or network boot to trigger heap out-of-bounds reads during boot-time filesystem parsing, potentially redirecting reads to arbitrary disk offsets.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.vulncheck.com/advisories/barebox-ext4-extent-parsing-out-of-bounds-readnvdThird Party Advisory
- github.com/barebox/barebox/releases/tag/v2026.04.0nvdRelease Notes
News mentions
0No linked articles in our index yet.