CVE-2025-70293

NameCVE-2025-70293
DescriptionAn issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1146625

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
u-boot (PTS)bookworm, bookworm (security)2023.01+dfsg-2+deb12u3vulnerable
trixie2025.01-3+deb13u1vulnerable
forky, sid2025.01-3.2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
u-bootsource(unstable)(unfixed)1146625

Notes

[trixie] - u-boot <no-dsa> (Minor issue)
https://www.openwall.com/lists/oss-security/2026/08/28/4
https://source.denx.de/u-boot/u-boot/-/commit/fc16c847a1c9c6e0ee1f605849cc500a04c21602 (v2026.04-rc1)

Search for package or bug name: Reporting problems