Denx / U-Boot
50 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-29009 | U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK | HIGH | 8.8 | Jul 8, 2026 |
| CVE-2026-29008 | U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine() | HIGH | 8.7 | Jul 8, 2026 |
| CVE-2026-29007 | U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c | MEDIUM | 6.9 | Jul 8, 2026 |
| CVE-2026-46728 | Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash. | HIGH | 8.8 | May 16, 2026 |
| CVE-2025-24857 | Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322,… | HIGH | 7.6 | Dec 10, 2025 |
| CVE-2025-45512 | A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files,… | MEDIUM | 6.5 | Aug 5, 2025 |
| CVE-2024-57259 | sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the p… | HIGH | 7.1 | Feb 18, 2025 |
| CVE-2024-57258 | Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_… | HIGH | 7.8 | Feb 18, 2025 |
| CVE-2024-57257 | A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting. | LOW | 2.4 | Feb 18, 2025 |
| CVE-2024-57256 | An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem wi… | HIGH | 7.1 | Feb 18, 2025 |
| CVE-2024-57255 | An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulti… | HIGH | 7.1 | Feb 18, 2025 |
| CVE-2024-57254 | An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem. | HIGH | 7.1 | Feb 18, 2025 |
| CVE-2024-42040 | Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on th… | HIGH | 8.1 | Aug 23, 2024 |
| CVE-2019-6268 | RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by read… | HIGH | 7.5 | Mar 8, 2024 |
| CVE-2022-2347 | Unchecked Download size in Uboot | HIGH | 7.7 | Sep 23, 2022 |
| CVE-2022-33967 | squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in… | HIGH | 7.8 | Jul 20, 2022 |
| CVE-2022-33103 | Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir(). | HIGH | 7.8 | Jul 1, 2022 |
| CVE-2022-34835 | In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the… | CRITICAL | 9.8 | Jun 29, 2022 |
| CVE-2022-30552 | Das U-Boot 2022.01 has a Buffer Overflow. | MEDIUM | 5.5 | Jun 8, 2022 |
| CVE-2022-30790 | Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. | HIGH | 7.8 | Jun 8, 2022 |
| CVE-2022-30767 | nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer o… | CRITICAL | 9.8 | May 16, 2022 |
| CVE-2021-27138 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT. | HIGH | 7.8 | Feb 17, 2021 |
| CVE-2021-27097 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. | HIGH | 7.8 | Feb 17, 2021 |
| CVE-2020-10648 | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a s… | HIGH | 7.8 | Mar 19, 2020 |
| CVE-2020-8432 | In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where co… | CRITICAL | 9.8 | Jan 29, 2020 |
Showing 1 to 25 of 50 CVEs