CVE-2021-27138
published 2021-02-17CVE-2021-27138: The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.09%
62.1th percentile
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | u-boot | < u-boot 2021.07+dfsg-2 (bookworm) | u-boot 2021.07+dfsg-2 (bookworm) |
| denx | u-boot | <= 2021.01 | — |
| denx | u-boot | — | — |
| denx | u-boot | >= 0 < 2021.01+dfsg-5+deb11u2 | 2021.01+dfsg-5+deb11u2 |
| denx | u-boot | >= 0 < 2021.07+dfsg-2 | 2021.07+dfsg-2 |
| denx | u-boot | >= 0 < 2021.07+dfsg-2 | 2021.07+dfsg-2 |
| denx | u-boot | >= 0 < 2021.07+dfsg-2 | 2021.07+dfsg-2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-27138: u-boot - The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresse...
vendor_debian·2021·CVSS 7.8
CVE-2021-27138 [HIGH] CVE-2021-27138: u-boot - The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresse...
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
Scope: local
bookworm: resolved (fixed in 2021.07+dfsg-2)
bullseye: resolved (fixed in 2021.01+dfsg-5+deb11u2)
forky: resolved (fixed in 2021.07+dfsg-2)
sid: resolved (fixed in 2021.07+dfsg-2)
trixie: resolved (fixed in 2021.07+dfsg-2)
GHSA
GHSA-grrh-mjp7-g52c: The boot loader in Das U-Boot before 2021
ghsa_unreviewed·2022-05-24
CVE-2021-27138 [HIGH] GHSA-grrh-mjp7-g52c: The boot loader in Das U-Boot before 2021
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
OSV
CVE-2021-27138: The boot loader in Das U-Boot before 2021
osv·2021-02-17·CVSS 7.8
CVE-2021-27138 [HIGH] CVE-2021-27138: The boot loader in Das U-Boot before 2021
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/u-boot/u-boot/commit/3f04db891a353f4b127ed57279279f851c6b4917https://github.com/u-boot/u-boot/commit/79af75f7776fc20b0d7eb6afe1e27c00fdb4b9b4https://github.com/u-boot/u-boot/commit/b6f4c757959f8850e1299a77c8e5713da78e8ec0https://github.com/u-boot/u-boot/commit/3f04db891a353f4b127ed57279279f851c6b4917https://github.com/u-boot/u-boot/commit/79af75f7776fc20b0d7eb6afe1e27c00fdb4b9b4https://github.com/u-boot/u-boot/commit/b6f4c757959f8850e1299a77c8e5713da78e8ec0https://lists.debian.org/debian-lts-announce/2025/09/msg00037.html
2021-02-17
Published