CVE-2024-42040

NameCVE-2024-42040
DescriptionBuffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1081557

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
u-boot (PTS)bullseye2021.01+dfsg-5vulnerable
bullseye (security)2021.01+dfsg-5+deb11u2vulnerable
bookworm2023.01+dfsg-2+deb12u2vulnerable
trixie2025.01-3vulnerable
forky, sid2025.01-3.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
u-bootsource(unstable)(unfixed)1081557

Notes

[trixie] - u-boot <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - u-boot <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - u-boot <postponed> (Minor issue; can be fixed in next update)
https://lists.denx.de/pipermail/u-boot/2024-August/562528.html
https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2024-004.txt

Search for package or bug name: Reporting problems