CVE-2019-13104 PUBLISHED

In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.

EPSS 0.29% · 52.2th percentile

Risk Scores

EPSS Score
0.29%
52.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSu-boot0, 2016.03+dfsg1-6ubuntu2, 2018.07~rc3+dfsg1-0ubuntu1~18.04.1
Ubuntu:20.04:LTSu-boot0, 2019.07+dfsg-1ubuntu3, 2019.07+dfsg-1ubuntu5

Timeline

References

Open in Interactive Console →