VendorsDenxu-bootany version
Vulnerabilities

Denx U-Boot any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

44CVEs
CVE-2019-11690
gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.
Published 2019-05-03 · Modified
5.9EPSS 0.012
CVE-2018-1000205
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.
Published 2018-06-26 · Modified
5.5EPSS 0.007
CVE-2017-3225
Das U-Boot's AES-CBC encryption feature uses a zero (0) initialization vector that may allow attacks against the underlying cryptographic implementation and allow an attacker to decrypt the data
Published 2018-07-24 · Modified
4.6EPSS 0.003
CVE-2024-57257
A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.
Published 2025-02-18 · Modified
2.4EPSS 0.003
← Prev2 / 2