VendorsDenxu-bootall versions
Vulnerabilities

Denx U-Boot

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2024-57255
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
Published 2025-02-18 · Modified
7.1EPSS 0.004
CVE-2026-29007
U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
Published 2026-07-08 · Analyzed
6.9EPSS 0.007
CVE-2025-45512
A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.
Published 2025-08-05 · Analyzed
6.5EPSS 0.003
CVE-2017-3226
Das U-Boot's AES-CBC encryption feature improperly handles an error condition and may allow attacks against the underlying cryptographic implementation and allow an attacker to decrypt the data
Published 2018-07-24 · Modified
6.4EPSS 0.003
CVE-2019-11690
gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.
Published 2019-05-03 · Modified
5.9EPSS 0.012
CVE-2018-1000205
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.
Published 2018-06-26 · Modified
5.5EPSS 0.007
CVE-2022-30552
Das U-Boot 2022.01 has a Buffer Overflow.
Published 2022-06-08 · Modified
5.5EPSS 0.004
CVE-2017-3225
Das U-Boot's AES-CBC encryption feature uses a zero (0) initialization vector that may allow attacks against the underlying cryptographic implementation and allow an attacker to decrypt the data
Published 2018-07-24 · Modified
4.6EPSS 0.003
CVE-2024-57257
A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.
Published 2025-02-18 · Modified
2.4EPSS 0.003
← Prev2 / 2