First published: Tue Aug 06 2019(Updated: )
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DENX U-Boot | >=2016.09<=2019.04 | |
DENX U-Boot | =2019.07 | |
DENX U-Boot | =2019.07-rc1 | |
DENX U-Boot | =2019.07-rc2 | |
DENX U-Boot | =2019.07-rc3 | |
DENX U-Boot | =2019.07-rc4 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13104 is a vulnerability in Das U-Boot versions 2016.11-rc1 through 2019.07-rc4 that can cause an underflow, leading to data corruption.
CVE-2019-13104 can allow an attacker to overwrite a large amount of data, including the whole stack, while reading a crafted ext4 filesystem.
CVE-2019-13104 has a severity rating of 7.8 (high).
Das U-Boot versions 2016.11-rc1 through 2019.07-rc4 are affected by CVE-2019-13104.
Installing the latest version of Das U-Boot that includes the fix for CVE-2019-13104 is recommended.