First published: Tue Nov 20 2018(Updated: )
DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DENX U-Boot | <=2018.07 | |
DENX U-Boot | =2018.09-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18440 is a vulnerability in DENX U-Boot through 2018.09-rc1 that allows for a locally exploitable buffer overflow via a crafted kernel image.
CVE-2018-18440 has a severity score of 7.8, which is considered high.
CVE-2018-18440 affects DENX U-Boot versions up to and including 2018.09-rc1.
The CWE identifier for CVE-2018-18440 is CWE-119.
To fix CVE-2018-18440, it is recommended to update DENX U-Boot to a version that is not affected by the vulnerability.