CVE-2020-13910: Critical severity barebox vulnerability
Published Jun 7, 2020
·Updated
Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfsreadreply in net/nfs.c because a field of an incoming network packet is directly used as a length field without any bounds check.
Affected Software
1 affected component
Pengutronix barebox<=2020.05.0
Remediation
Event History
Jun 7, 2020
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13910?
CVE-2020-13910 is classified as a medium severity vulnerability due to its potential to cause out-of-bounds read issues.
2
How do I fix CVE-2020-13910?
To fix CVE-2020-13910, you should update Barebox to a version later than v2020.05.0 that includes the necessary patches.
3
What impacts can CVE-2020-13910 have on my system?
CVE-2020-13910 can potentially expose sensitive data through out-of-bounds reads, leading to information leakage.
4
Which versions of Barebox are affected by CVE-2020-13910?
CVE-2020-13910 affects all versions of Barebox up to and including v2020.05.0.
5
Is there a workaround for CVE-2020-13910?
There are no official workarounds for CVE-2020-13910; updating to a secure version is recommended.