CVE-2021-37847: High severity Pengutronix barebox vulnerability
Published Aug 2, 2021
·Updated
crypto/digest.c in Pengutronix barebox through 2021.07.0 leaks timing information because memcmp is used during digest verification.
Affected Software
1 affected component
Pengutronix barebox<=2021.07.0
Remediation
Event History
Aug 2, 2021
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-37847?
CVE-2021-37847 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2021-37847?
To fix CVE-2021-37847, update to a version of barebox later than 2021.07.0 that addresses this timing information leak.
3
What component is affected by CVE-2021-37847?
CVE-2021-37847 affects the digest verification component within the Pengutronix barebox.
4
What type of vulnerability is CVE-2021-37847?
CVE-2021-37847 is a timing attack vulnerability due to the use of memcmp in digest verification.
5
What software versions are affected by CVE-2021-37847?
Barebox versions up to and including 2021.07.0 are affected by CVE-2021-37847.