CVE-2019-14195: Critical severity DENX U-Boot vulnerability
Published Jul 31, 2019
·Updated
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfsreadlinkreply in the "else" block after calculating the new path length.
Affected Software
1 affected component
DENX U-Boot<=2019.07
Event History
Jul 31, 2019
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·02:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-14195?
The severity of CVE-2019-14195 is critical.
2
What is the affected software for CVE-2019-14195?
The affected software for CVE-2019-14195 is DENX U-Boot up to and including version 2019.07.
3
What is the CWE ID for CVE-2019-14195?
The CWE ID for CVE-2019-14195 is CWE-787.
4
How can I fix CVE-2019-14195?
To fix CVE-2019-14195, it is recommended to update to a version of Das U-Boot after 2019.07.
5
Are there any references for CVE-2019-14195?
Yes, there are references available for CVE-2019-14195. You can find them at the following links: [1] https://blog.semmle.com/uboot-rce-nfs-vulnerability/ [2] https://gitlab.com/u-boot/u-boot