VYPR

U Boot

by Denx

Source repositories

CVEs (50)

  • CVE-2019-13103HigJul 29, 2019
    risk 0.39cvss 7.1epss 0.00

    A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.

  • CVE-2019-11690MedMay 3, 2019
    risk 0.38cvss 5.9epss 0.01

    gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.

  • CVE-2022-30552MedJun 8, 2022
    risk 0.36cvss 5.5epss 0.00

    Das U-Boot 2022.01 has a Buffer Overflow.

  • CVE-2018-1000205MedJun 26, 2018
    risk 0.36cvss 5.5epss 0.01

    U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.

  • CVE-2017-3225MedJul 24, 2018
    risk 0.30cvss 4.6epss 0.00

    Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this environment encryption mode, U-Boot's use of a zero initialization vector may allow attacks against the underlying cryptographic implementation and allow an…

  • CVE-2026-29007MedJul 8, 2026
    risk 0.27cvss 5.3epss 0.01

    U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP…

  • CVE-2024-57257LowFeb 18, 2025
    risk 0.13cvss 2.0epss 0.00

    A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.

  • CVE-2022-30767CriMay 16, 2022
    risk 0.00cvss 9.8epss 0.03

    nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.

  • CVE-2021-27138HigFeb 17, 2021
    risk 0.00cvss 7.8epss 0.01

    The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.

  • CVE-2021-27097HigFeb 17, 2021
    risk 0.00cvss 7.8epss 0.01

    The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.

Page 3 of 3