Unbounded Memory Copy Issue in Das U-Boot NFSv2 Implementation
CVE-2019-14194

9.8CRITICAL

Key Information:

Vendor

Denx

Status
Vendor
CVE Published:
31 July 2019

What is CVE-2019-14194?

An unbounded memcpy vulnerability has been identified in Das U-Boot up to version 2019.07, specifically during the NFSv2 operation. This flaw occurs in the nfs_read_reply function where a length check is improperly implemented, allowing for potential exploitation that could affect the stability and security of systems utilizing this bootloader. If left unpatched, this issue could enable attackers to execute arbitrary code or manipulate memory processes, posing significant risks to affected deployments.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.