CVE-2019-13105: Double Free
Published Aug 6, 2019
·Updated
Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
Affected Software
4 affected components
DENX U-Boot=2019.07-rc1
DENX U-Boot=2019.07-rc2
DENX U-Boot=2019.07-rc3
DENX U-Boot=2019.07-rc4
Remediation
Patch Available
Patch Available
Event History
Aug 6, 2019
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-13105.
2
What is the severity rating of CVE-2019-13105?
CVE-2019-13105 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2019-13105?
Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 are affected.
4
What is the impact of CVE-2019-13105?
CVE-2019-13105 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
5
How can I fix CVE-2019-13105?
To fix CVE-2019-13105, it is recommended to update to a patched version of Das U-Boot.