CVE-2020-10648 PUBLISHED

Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.

EPSS 0.12% · 31.4th percentile

Risk Scores

EPSS Score
0.12%
31.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSu-boot0, 2015.04+dfsg1-2ubuntu1, 2015.10+dfsg1-2
Ubuntu:18.04:LTSu-boot0, 2016.03+dfsg1-6ubuntu2, 2018.07~rc3+dfsg1-0ubuntu1~18.04.1
Ubuntu:20.04:LTSu-boot0, 2019.07+dfsg-1ubuntu3, 2019.07+dfsg-1ubuntu5

Timeline

References

Open in Interactive Console →