Boot Loader Vulnerability in Das U-Boot
CVE-2021-27138

7.8HIGH

Key Information:

Vendor

Denx

Status
Vendor
CVE Published:
17 February 2021

What is CVE-2021-27138?

The boot loader in Das U-Boot versions prior to 2021.04-rc2 is susceptible to a flaw that arises from its improper handling of unit addresses within a Flattened Image Tree (FIT). This oversight can lead to unforeseen behaviors during the boot process, potentially affecting system integrity and stability. It is essential for users and developers relying on Das U-Boot to address this vulnerability to enhance their security posture.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.