Medium severity6.2NVD Advisory· Published May 11, 2026· Updated May 13, 2026
CVE-2026-34962
CVE-2026-34962
Description
barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry length values are non-zero. Attackers can supply a malicious ext4 filesystem image with a crafted directory entry containing a direntlen value of 0 to cause an infinite loop during directory listing or path resolution, resulting in the boot process hanging indefinitely.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.vulncheck.com/advisories/barebox-ext4-directory-parsing-infinite-loop-denial-of-servicenvdThird Party Advisory
- github.com/barebox/barebox/releases/tag/v2026.04.0nvdRelease Notes
News mentions
0No linked articles in our index yet.