CVE-2019-14194: Critical severity DENX U-Boot vulnerability
Published Jul 31, 2019
·Updated
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfsreadreply when calling storeblock in the NFSv2 case.
Affected Software
1 affected component
DENX U-Boot<=2019.07
Event History
Jul 31, 2019
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·04:41 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-14194?
CVE-2019-14194 is a vulnerability discovered in Das U-Boot through 2019.07 that allows an unbounded memcpy with a failed length check.
2
How severe is CVE-2019-14194?
CVE-2019-14194 has a severity rating of 9.8 (Critical).
3
What software is affected by CVE-2019-14194?
The affected software is DENX U-Boot version up to and including 2019.07.
4
What is the CWE of CVE-2019-14194?
The CWE of CVE-2019-14194 is CWE-787 (Out-of-bounds Write).
5
Are there any references for CVE-2019-14194?
Yes, you can find more information about CVE-2019-14194 at https://blog.semmle.com/uboot-rce-nfs-vulnerability/ and https://gitlab.com/u-boot/u-boot.