HIGH
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem
Published Aug 6, 2019
7.8
HIGHCVSS 3.1
EPSS 1.11%
Description
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-577017.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4645 Advisory
- https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75 x_refsource_MISCThird Party Advisory
- https://github.com/u-boot/u-boot/commits/master x_refsource_MISCPatchThird Party Advisory
- https://lists.denx.de/pipermail/u-boot/2019-July/375514.html x_refsource_MISCMailing ListPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00002.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00004.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://cert-portal.siemens.com/productcert/html/ssa-577017.html | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4645 | Advisory | |
| https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75 | x_refsource_MISCThird Party Advisory | |
| https://github.com/u-boot/u-boot/commits/master | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.denx.de/pipermail/u-boot/2019-July/375514.html | x_refsource_MISCMailing ListPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 6, 2019
Updated May 12, 2026
Reserved Jun 30, 2019
Link CVE-2019-13104
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-4645 Assigner mitre
Published Aug 6, 2019
Updated May 12, 2026
Exploited since n/a
Link EUVD-2019-4645