CVE-2018-3968: High severity DENX U-Boot vulnerability
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3968?
The severity of CVE-2018-3968 is high (7 out of 10).
Which software versions are affected by CVE-2018-3968?
The affected versions of the software are from 2013.07-rc1 to 2014.07-rc2.
How does CVE-2018-3968 impact U-Boot's verified boot protection?
The vulnerability allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-3968?
The Common Weakness Enumeration (CWE) ID for CVE-2018-3968 is CWE-347.
Is there a fix available for CVE-2018-3968?
It is recommended to update to a fixed version of Das U-Boot to mitigate CVE-2018-3968.