Denx

U-boot

53 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 29.09.2026 10:17:11
  • Zuletzt bearbeitet 30.09.2026 19:38:27

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This ...

  • EPSS 0.18%
  • Veröffentlicht 26.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 16:04:24

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lea...

  • EPSS 0.46%
  • Veröffentlicht 26.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 16:04:24

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memor...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 08.07.2026 16:16:04
  • Zuletzt bearbeitet 24.07.2026 18:16:52

U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning m...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 08.07.2026 16:14:41
  • Zuletzt bearbeitet 22.07.2026 18:32:12

U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated dat...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 08.07.2026 16:11:25
  • Zuletzt bearbeitet 22.07.2026 18:31:40

U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a misma...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 16.05.2026 21:26:49
  • Zuletzt bearbeitet 11.09.2026 15:55:09

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

  • EPSS 0.26%
  • Veröffentlicht 10.12.2025 00:00:00
  • Zuletzt bearbeitet 21.01.2026 19:14:47

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 05.08.2025 19:15:32
  • Zuletzt bearbeitet 02.10.2025 17:35:37

A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.

  • EPSS 0.37%
  • Veröffentlicht 18.02.2025 23:15:09
  • Zuletzt bearbeitet 12.05.2026 13:16:22

An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrit...