CVE-2019-13106 PUBLISHED

Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.

EPSS 0.84% · 74.7th percentile

Risk Scores

EPSS Score
0.84%
74.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSu-boot2021.01+dfsg-3ubuntu0~20.04.1, 0, 2019.07+dfsg-1ubuntu3
Ubuntu:18.04:LTSu-boot0, 2016.03+dfsg1-6ubuntu2, 2018.07~rc3+dfsg1-0ubuntu1~18.04.1

Timeline

References

Open in Interactive Console →