CVE-2024-42040
published 2024-08-23CVE-2024-42040: Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on…
PriorityP341high8.1CVSS 3.1
AVAACLPRNUINSUCHINAH
EPSS
0.60%
44.6th percentile
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | u-boot | — | — |
| denx | u-boot | <= 2025.10 | — |
| denx | u-boot | >= 0 < 2022.01+dfsg-2ubuntu2.7 | 2022.01+dfsg-2ubuntu2.7 |
| denx | u-boot | >= 0 < 2025.10-0ubuntu0.24.04.2 | 2025.10-0ubuntu0.24.04.2 |
| msrc | azl3_qemu_8.2.0-16_on_azure_linux_3.0 | — | — |
| msrc | cbl2_qemu_6.2.0-24_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
U-Boot vulnerabilities
vendor_ubuntu·2026-02-23·CVSS 8.1
CVE-2024-57257 [HIGH] U-Boot vulnerabilities
Title: U-Boot vulnerabilities
Summary: Several security issues were fixed in U-Boot.
Simon Diepold discovered that U-Boot incorrectly handled certain DHCP
responses. An attacker on the local network could possibly use this issue
to obtain sensitive memory contents. (CVE-2024-42040)
It was discovered that U-Boot incorrectly handled symlink size calculations
in squashfs file systems. An attacker could use this issue with a specially
crafted squashfs file system to cause U-Boot to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2024-57254)
It was discovered that U-Boot incorrectly handled inode size calculations
in squashfs file systems. An attacker could use this issue with a specially
crafted squashfs file system to cause U-Boot to crash, resulting in a denial
o
Microsoft
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four
vendor_msrc·2024-08-13·CVSS 8.1
CVE-2024-42040 [HIGH] CWE-120 Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we beg
Debian
CVE-2024-42040: u-boot - Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initia...
vendor_debian·2024·CVSS 8.1
CVE-2024-42040 [HIGH] CVE-2024-42040: u-boot - Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initia...
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
u-boot vulnerabilities
osv·2026-02-23·CVSS 8.1
CVE-2024-42040 [HIGH] u-boot vulnerabilities
u-boot vulnerabilities
Simon Diepold discovered that U-Boot incorrectly handled certain DHCP
responses. An attacker on the local network could possibly use this issue
to obtain sensitive memory contents. (CVE-2024-42040)
It was discovered that U-Boot incorrectly handled symlink size calculations
in squashfs file systems. An attacker could use this issue with a specially
crafted squashfs file system to cause U-Boot to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2024-57254)
It was discovered that U-Boot incorrectly handled inode size calculations
in squashfs file systems. An attacker could use this issue with a specially
crafted squashfs file system to cause U-Boot to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2024-57255)
It was
GHSA
GHSA-xh96-vq46-m9ww: Buffer Overflow vulnerability in the net/bootp
ghsa_unreviewed·2024-08-23
CVE-2024-42040 [HIGH] CWE-120 GHSA-xh96-vq46-m9ww: Buffer Overflow vulnerability in the net/bootp
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
OSV
CVE-2024-42040: Buffer Overflow vulnerability in the net/bootp
osv·2024-08-23·CVSS 8.1
CVE-2024-42040 [HIGH] CVE-2024-42040: Buffer Overflow vulnerability in the net/bootp
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-23
Published