First published: Sun Jun 07 2020(Updated: )
Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field without any bounds check.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barebox | <=2020.05.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13910 is classified as a medium severity vulnerability due to its potential to cause out-of-bounds read issues.
To fix CVE-2020-13910, you should update Barebox to a version later than v2020.05.0 that includes the necessary patches.
CVE-2020-13910 can potentially expose sensitive data through out-of-bounds reads, leading to information leakage.
CVE-2020-13910 affects all versions of Barebox up to and including v2020.05.0.
There are no official workarounds for CVE-2020-13910; updating to a secure version is recommended.