Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
2019-08-06T20:15:12.110
2024-11-21T04:24:11.980
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:C
8.6
8.5
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | denx | u-boot | ≤ 2019.04 | Yes |
| Application | denx | u-boot | 2019.07 | Yes |
| Application | denx | u-boot | 2019.07 | Yes |
| Application | denx | u-boot | 2019.07 | Yes |
| Application | denx | u-boot | 2019.07 | Yes |
| Application | denx | u-boot | 2019.07 | Yes |
| Operating System | opensuse | leap | 15.0 | Yes |
| Operating System | opensuse | leap | 15.1 | Yes |