Debian U-Boot vulnerabilities

45 known vulnerabilities affecting debian/u-boot.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH14MEDIUM2LOW13

Vulnerabilities

Page 2 of 3
CVE-2019-14201CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14201 [CRITICAL] CVE-2019-14201: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu... An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixed i
debian
CVE-2019-14196CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14196 [CRITICAL] CVE-2019-14196: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem... An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2021.01+dfsg-5+deb11u1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixed in 2020.01+dfsg-
debian
CVE-2019-11059CRITICALCVSS 9.8fixed in u-boot 2019.01+dfsg-6 (bookworm)2019
CVE-2019-11059 [CRITICAL] CVE-2019-11059: u-boot - Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, res... Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow. Scope: local bookworm: resolved (fixed in 2019.01+dfsg-6) bullseye: resolved (fixed in 2019.01+dfsg-6) forky: resolved (fixed in 2019.01+dfsg-6) sid: resolved (fixed in 2019.01+dfsg-6) trixie: resolved (fixed in 2019.01+dfsg-6)
debian
CVE-2019-14193CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14193 [CRITICAL] CVE-2019-14193: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem... An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.
debian
CVE-2019-14203CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14203 [CRITICAL] CVE-2019-14203: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu... An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixed in
debian
CVE-2019-14199CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14199 [CRITICAL] CVE-2019-14199: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem... An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixe
debian
CVE-2019-14192CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14192 [CRITICAL] CVE-2019-14192: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem... An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in
debian
CVE-2019-14197CRITICALCVSS 9.1fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14197 [CRITICAL] CVE-2019-14197: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of... An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixed in 2020.01+dfsg-1)
debian
CVE-2019-14200CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14200 [CRITICAL] CVE-2019-14200: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu... An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixed i
debian
CVE-2019-14204CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14204 [CRITICAL] CVE-2019-14204: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu... An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixe
debian
CVE-2019-14198CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14198 [CRITICAL] CVE-2019-14198: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem... An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie:
debian
CVE-2019-14202CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14202 [CRITICAL] CVE-2019-14202: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is a stack-based bu... An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixed
debian
CVE-2019-14194CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14194 [CRITICAL] CVE-2019-14194: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem... An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie:
debian
CVE-2019-14195CRITICALCVSS 9.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-14195 [CRITICAL] CVE-2019-14195: u-boot - An issue was discovered in Das U-Boot through 2019.07. There is an unbounded mem... An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01
debian
CVE-2019-13106LOWCVSS 7.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-13106 [HIGH] CVE-2019-13106: u-boot - Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while... Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1)
debian
CVE-2019-11690LOWCVSS 5.9fixed in u-boot 2019.01+dfsg-6 (bookworm)2019
CVE-2019-11690 [MEDIUM] CVE-2019-11690: u-boot - gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an sra... gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device. Scope: local bookworm: resolved (fixed in 2019.01+dfsg-6) bullseye: resolved (fixed in 201
debian
CVE-2019-13105LOWCVSS 7.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-13105 [HIGH] CVE-2019-13105: u-boot - Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached blo... Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 2020.01+dfsg-1) trixie: resolved (fixed in 2020.01+dfsg-1)
debian
CVE-2019-13103LOWCVSS 7.1fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-13103 [HIGH] CVE-2019-13103: u-boot - A crafted self-referential DOS partition table will cause all Das U-Boot version... A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: reso
debian
CVE-2019-13104LOWCVSS 7.8fixed in u-boot 2020.01+dfsg-1 (bookworm)2019
CVE-2019-13104 [HIGH] CVE-2019-13104: u-boot - In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause m... In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem. Scope: local bookworm: resolved (fixed in 2020.01+dfsg-1) bullseye: resolved (fixed in 2020.01+dfsg-1) forky: resolved (fixed in 2020.01+dfsg-1) sid: resolved (fixed in 20
debian
CVE-2018-3968HIGHCVSS 7.0fixed in u-boot 2014.07+dfsg1-1 (bookworm)2018
CVE-2018-3968 [HIGH] CVE-2018-3968: u-boot - An exploitable vulnerability exists in the verified boot protection of the Das U... An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to b
debian