DescriptionDENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.
NVD severityhigh

Source PackageReleaseVersionStatus
u-boot (PTS)stretch2016.11+dfsg1-4vulnerable
bullseye, sid2021.01+dfsg-4vulnerable

No security impact as supported/packaged in Debian

