cbcvebase.

Denx U-Boot vulnerabilities

49 known vulnerabilities affecting denx/u-boot.

Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH19MEDIUM10LOW1

Vulnerabilities

Page 2 of 3
CVE-2019-14198P3CRITICALCVSS 9.8≤ 2019.072019-07-31
CVE-2019-14198 [CRITICAL] CWE-787 CVE-2019-14198: An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed le An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case.
nvdosv
CVE-2024-42040P3HIGHCVSS 8.1≤ 2025.102024-08-23
CVE-2024-42040 [HIGH] CWE-120 CVE-2024-42040: Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (38 Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
nvdosv
CVE-2025-24857P3HIGHCVSS 7.6fixed in 2017.112025-12-10
CVE-2025-24857 [HIGH] CWE-284 CVE-2025-24857: Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) b Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.
nvdosv
CVE-2019-13106P3HIGHCVSS 7.8≥ 2016.09, ≤ 2019.04v2019.072019-08-06
CVE-2019-13106 [HIGH] CWE-787 CVE-2019-13106: Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted e Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
nvdosv
CVE-2020-10648P3HIGHCVSS 7.8fixed in 2018.03v2020.012020-03-19
CVE-2020-10648 [HIGH] CWE-20 CVE-2020-10648: Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently bo Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
nvdosv
CVE-2026-33243P3HIGHCVSS 8.2≥ 2013.07, < 2026.04v2026.042026-03-20
CVE-2026-33243 [HIGH] CWE-345 CVE-2026-33243: barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corr barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) sets the hashed-node
nvd
CVE-2024-57258P3HIGHCVSS 7.8≤ 2024.102025-02-18
CVE-2024-57258 [HIGH] CWE-190 CVE-2024-57258: Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.
nvdosv
CVE-2018-18440P3HIGHCVSS 7.8≤ 2018.07v2018.092018-11-20
CVE-2018-18440 [HIGH] CWE-119 CVE-2018-18440: DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.
nvd
CVE-2022-30790P3HIGHCVSS 7.8v2022.012022-06-08
CVE-2022-30790 [HIGH] CVE-2022-30790: Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
nvdosv
CVE-2022-33967P3HIGHCVSS 7.8v2020.10v2021.01+4 more2022-07-20
CVE-2022-33967 [HIGH] CWE-787 CVE-2022-33967: squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a h squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.
nvdosv
CVE-2022-33103P3HIGHCVSS 7.8≥ 2020.10, < 2022.07v2022.072022-07-01
CVE-2022-33103 [HIGH] CWE-787 CVE-2022-33103: Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the fu Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
nvdosv
CVE-2019-13104P3HIGHCVSS 7.8≥ 2016.09, ≤ 2019.04v2019.072019-08-06
CVE-2019-13104 [HIGH] CWE-191 CVE-2019-13104: In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
nvdosv
CVE-2025-45512P3MEDIUMCVSS 6.5v1.1.32025-08-05
CVE-2025-45512 [MEDIUM] CWE-77 CVE-2025-45512: A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.
nvd
CVE-2019-13105P4HIGHCVSS 7.8v2019.072019-08-06
CVE-2019-13105 [HIGH] CWE-415 CVE-2019-13105: Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when list Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
nvdosv
CVE-2021-27138P4HIGHCVSS 7.8≤ 2021.01v2021.042021-02-17
CVE-2021-27138 [HIGH] CVE-2021-27138: The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT. The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
nvdosv
CVE-2021-27097P4HIGHCVSS 7.8≤ 2021.01v2021.042021-02-17
CVE-2021-27097 [HIGH] CVE-2021-27097: The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
nvdosv
CVE-2026-29007P4MEDIUMCVSS 5.3fixed in 2026.04v2026.04-rc1+2 more2026-07-08
CVE-2026-29007 [MEDIUM] CWE-125 CVE-2026-29007: U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (n U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length
nvd
CVE-2018-3968P4HIGHCVSS 7.0≥ 2013.07, ≤ 2014.07v2013.07+1 more2019-03-21
CVE-2018-3968 [HIGH] CWE-347 CVE-2018-3968: An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2 An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local att
nvdosv
CVE-2022-2347P4HIGHCVSS 7.1≥ 2012.10, ≤ 2022.072022-09-23
CVE-2022-2347 [HIGH] CWE-122 CVE-2022-2347: There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the le There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, th
nvdosv
CVE-2019-11690P4MEDIUMCVSS 5.9≥ 2014.04, ≤ 2019.042019-05-03
CVE-2019-11690 [MEDIUM] CWE-330 CVE-2019-11690: gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allow gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.
nvdosv
Denx U-Boot vulnerabilities | cvebase