CVE-2019-14192: Integer Underflow
Published Jul 31, 2019
·Updated
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a netprocessreceivedpacket integer underflow during an ncinputpacket call.
Affected Software
1 affected component
DENX U-Boot<=2019.07
Event History
Jul 31, 2019
CVE Published
via MITRE·12:18 PM
Data Sourced
via MITRE·12:18 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-14192?
CVE-2019-14192 is a vulnerability in Das U-Boot through 2019.07 that allows for remote code execution.
2
How severe is CVE-2019-14192?
CVE-2019-14192 is rated as critical with a severity score of 9.8 out of 10.
3
What is the affected software for CVE-2019-14192?
The affected software is DENX U-Boot version up to and inclusive of 2019.07.
4
How can I fix CVE-2019-14192?
To fix CVE-2019-14192, users should update to a patched version of Das U-Boot.
5
Where can I find more information about CVE-2019-14192?
You can find more information about CVE-2019-14192 at the following references: [1](https://blog.semmle.com/uboot-rce-nfs-vulnerability/), [2](https://gitlab.com/u-boot/u-boot)