CVE-2019-13104: Integer Underflow
Published Aug 6, 2019
·Updated
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
Affected Software
8 affected components
DENX U-Boot>=2016.09<=2019.04
DENX U-Boot=2019.07
DENX U-Boot=2019.07-rc1
DENX U-Boot=2019.07-rc2
DENX U-Boot=2019.07-rc3
DENX U-Boot=2019.07-rc4
openSUSE Leap=15.0
openSUSE Leap=15.1
Remediation
Patch Available
Patch Available
Event History
Aug 6, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-13104?
CVE-2019-13104 is a vulnerability in Das U-Boot versions 2016.11-rc1 through 2019.07-rc4 that can cause an underflow, leading to data corruption.
2
How does CVE-2019-13104 affect my system?
CVE-2019-13104 can allow an attacker to overwrite a large amount of data, including the whole stack, while reading a crafted ext4 filesystem.
3
What is the severity of CVE-2019-13104?
CVE-2019-13104 has a severity rating of 7.8 (high).
4
Which software versions are affected by CVE-2019-13104?
Das U-Boot versions 2016.11-rc1 through 2019.07-rc4 are affected by CVE-2019-13104.
5
How can I fix CVE-2019-13104?
Installing the latest version of Das U-Boot that includes the fix for CVE-2019-13104 is recommended.