CVE-2018-18440: Buffer Overflow
Published Nov 20, 2018
·Updated
DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.
Affected Software
2 affected components
DENX U-Boot<=2018.07
DENX U-Boot=2018.09-rc1
Event History
Nov 20, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-18440?
CVE-2018-18440 is a vulnerability in DENX U-Boot through 2018.09-rc1 that allows for a locally exploitable buffer overflow via a crafted kernel image.
2
How severe is CVE-2018-18440?
CVE-2018-18440 has a severity score of 7.8, which is considered high.
3
How does CVE-2018-18440 affect DENX U-Boot?
CVE-2018-18440 affects DENX U-Boot versions up to and including 2018.09-rc1.
4
What is the Common Weakness Enumeration (CWE) identifier for CVE-2018-18440?
The CWE identifier for CVE-2018-18440 is CWE-119.
5
How can I fix CVE-2018-18440?
To fix CVE-2018-18440, it is recommended to update DENX U-Boot to a version that is not affected by the vulnerability.