CVE-2019-13106: Buffer Overflow
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13106?
CVE-2019-13106 is a vulnerability in Das U-Boot versions 2016.09 through 2019.07-rc4 that can lead to a stack buffer overflow and likely code execution.
How severe is CVE-2019-13106?
CVE-2019-13106 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2019-13106?
Das U-Boot versions 2016.09 through 2019.07-rc4 are affected by CVE-2019-13106.
How can CVE-2019-13106 be exploited?
CVE-2019-13106 can be exploited by reading a crafted ext4 filesystem that causes a stack buffer overflow.
Are there any references for CVE-2019-13106?
Yes, you can find more information about CVE-2019-13106 at the following links: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00002.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00004.html), [Reference 3](https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75).