CVE-2019-14197: Critical severity DENX U-Boot vulnerability
Published Jul 31, 2019
·Updated
An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfsreadreply.
Affected Software
1 affected component
DENX U-Boot<=2019.07
Event History
Jul 31, 2019
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·10:13 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-14197?
CVE-2019-14197 is a vulnerability discovered in Das U-Boot through 2019.07 that allows an attacker to read out-of-bounds data at nfs_read_reply.
2
What is the severity of CVE-2019-14197?
The severity of CVE-2019-14197 is critical with a CVSS score of 9.1.
3
How does CVE-2019-14197 affect DENX U-Boot?
CVE-2019-14197 affects DENX U-Boot versions up to and including 2019.07.
4
Is there a patch available for CVE-2019-14197?
Yes, patches for CVE-2019-14197 are available on the official GitLab repository for U-Boot.
5
Where can I find more information about CVE-2019-14197?
You can find more information about CVE-2019-14197 in the blog post by Semmle and the official GitLab repository for U-Boot.