Debian U-Boot vulnerabilities
38 known vulnerabilities affecting debian/u-boot.
Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH13MEDIUM2LOW7
Vulnerabilities
Page 1 of 2
CVE-2020-8432P3LOWCVSS 9.8fixed in u-boot 2020.01+dfsg-2 (bookworm)2020
CVE-2020-8432 [CRITICAL] CVE-2020-8432: u-boot - In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_...
In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static analysis.
Scope: local
bookworm: resolved (fixed in 20
debian
CVE-2022-34835P3CRITICALCVSS 9.8fixed in u-boot 2022.07+dfsg-1 (bookworm)2022
CVE-2022-34835 [CRITICAL] CVE-2022-34835: u-boot - In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant sta...
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
Scope: local
bookworm: resolved (fixed in 2022.07+dfsg-1)
bullseye: resolved (fixed in 2021.01+dfsg-5+deb11u1)
forky: resolved (fixed in 2022.07+dfsg-1)
sid
debian
CVE-2022-30767P3CRITICALCVSS 9.8fixed in u-boot 2022.07+dfsg-1 (bookworm)2022
CVE-2022-30767 [CRITICAL] CVE-2022-30767: u-boot - nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07...
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
Scope: local
bookworm: resolved (fixed in 2022.07+dfsg-1)
bullseye: resolved (fixed in 2021.01+dfsg-5+deb11u1)
forky: resolve
debian
CVE-2019-14201P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14201 [CRITICAL] CVE-2019-14201: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu...
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie: resolved (fixed i
debian
CVE-2019-14203P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14203 [CRITICAL] CVE-2019-14203: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu...
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie: resolved (fixed in
debian
CVE-2019-14200P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14200 [CRITICAL] CVE-2019-14200: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu...
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie: resolved (fixed i
debian
CVE-2019-14204P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14204 [CRITICAL] CVE-2019-14204: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu...
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie: resolved (fixe
debian
CVE-2019-14202P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14202 [CRITICAL] CVE-2019-14202: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu...
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie: resolved (fixed
debian
CVE-2019-14192P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14192 [CRITICAL] CVE-2019-14192: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem...
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in
debian
CVE-2019-14197P3CRITICALCVSS 9.1fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14197 [CRITICAL] CVE-2019-14197: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of...
An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie: resolved (fixed in 2020.01+dfsg-1)
debian
CVE-2019-14199P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14199 [CRITICAL] CVE-2019-14199: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem...
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixe
debian
CVE-2019-11059P3CRITICALCVSS 9.8fixed in u-boot 2019.01+dfsg-6 (bookworm)2019
CVE-2019-11059 [CRITICAL] CVE-2019-11059: u-boot - Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, res...
Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2019.01+dfsg-6)
bullseye: resolved (fixed in 2019.01+dfsg-6)
forky: resolved (fixed in 2019.01+dfsg-6)
sid: resolved (fixed in 2019.01+dfsg-6)
trixie: resolved (fixed in 2019.01+dfsg-6)
debian
CVE-2019-14193P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14193 [CRITICAL] CVE-2019-14193: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem...
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.
debian
CVE-2019-14195P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14195 [CRITICAL] CVE-2019-14195: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem...
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01
debian
CVE-2019-14196P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14196 [CRITICAL] CVE-2019-14196: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem...
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2021.01+dfsg-5+deb11u1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie: resolved (fixed in 2020.01+dfsg-
debian
CVE-2019-14198P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14198 [CRITICAL] CVE-2019-14198: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem...
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie:
debian
CVE-2019-14194P3CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14194 [CRITICAL] CVE-2019-14194: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem...
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
trixie:
debian
CVE-2025-24857P3HIGHCVSS 7.6fixed in u-boot 2017.11+dfsg1-2 (bookworm)2025
CVE-2025-24857 [HIGH] CVE-2025-24857: u-boot - Improper access control for volatile memory containing boot code in Universal Bo...
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 2017.11+dfsg1-2)
bullseye: resolved (fixed in 2017.11+dfsg1-2)
forky: resolve
debian
CVE-2019-13106P3LOWCVSS 7.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-13106 [HIGH] CVE-2019-13106: u-boot - Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while...
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
Scope: local
bookworm: resolved (fixed in 2020.01+dfsg-1)
bullseye: resolved (fixed in 2020.01+dfsg-1)
forky: resolved (fixed in 2020.01+dfsg-1)
sid: resolved (fixed in 2020.01+dfsg-1)
debian
CVE-2020-10648P3HIGHCVSS 7.8fixed in u-boot 2020.04+dfsg-1 (bookworm)2020
CVE-2020-10648 [HIGH] CVE-2020-10648: u-boot - Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions...
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
Scope: local
bookworm: resolved (fixed in 2020.04+dfsg-1)
bullseye: resolved (fixed in 2020.04+dfsg-1)
forky: resolved (fixed in 2020.04+dfsg-1)
sid: resolved
debian
1 / 2Next →