CVE-2019-14201: Buffer Overflow
Published Jul 31, 2019
·Updated
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfshandler reply helper function: nfslookupreply.
Affected Software
1 affected component
DENX U-Boot<=2019.07
Event History
Jul 31, 2019
CVE Published
via MITRE·12:13 PM
Data Sourced
via MITRE·12:13 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·04:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-14201?
The severity of CVE-2019-14201 is critical with a CVSS score of 9.8.
2
How does CVE-2019-14201 affect Das U-Boot?
CVE-2019-14201 affects Das U-Boot versions up to and including 2019.07.
3
What is the vulnerability description of CVE-2019-14201?
CVE-2019-14201 is a stack-based buffer overflow vulnerability in the nfs_handler reply helper function.
4
Are there any known references related to CVE-2019-14201?
Yes, you can find more information about CVE-2019-14201 at the following references: [https://blog.semmle.com/uboot-rce-nfs-vulnerability/](https://blog.semmle.com/uboot-rce-nfs-vulnerability/) and [https://gitlab.com/u-boot/u-boot](https://gitlab.com/u-boot/u-boot).
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-14201?
The Common Weakness Enumeration (CWE) ID for CVE-2019-14201 is CWE-119 and CWE-787.