Information on source package u-boot

Available versions

ReleaseVersion
bookworm2023.01+dfsg-2+deb12u3
trixie2025.01-3
forky2025.01-3.2
sid2025.01-3.2

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-46728fixedvulnerable (no DSA)fixedfixedDas U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verif ...
CVE-2026-29009vulnerablevulnerable (no DSA)vulnerablevulnerableU-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in ...
CVE-2026-29008vulnerablevulnerable (no DSA)vulnerablevulnerableU-Boot through 2026.04-rc3 contains an integer underflow vulnerability ...
CVE-2026-29007vulnerablevulnerable (no DSA)vulnerablevulnerableU-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerabilit ...
CVE-2025-70293vulnerablevulnerable (no DSA)vulnerablevulnerableAn issue was discovered in Denx U-Boot before 2026.04. An integer over ...
CVE-2025-70292vulnerablevulnerable (no DSA)vulnerablevulnerable
CVE-2025-70291vulnerablevulnerable (no DSA)vulnerablevulnerable
CVE-2025-70290vulnerablevulnerable (no DSA)vulnerablevulnerableAn issue was discovered in Denx U-Boot before 2026.04. An integer over ...
CVE-2024-42040fixedvulnerable (no DSA, postponed)fixedfixedBuffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from ...

Open unimportant issues

BugbookwormtrixieforkysidDescription
CVE-2025-45512vulnerablevulnerablevulnerablevulnerableA lack of signature verification in the bootloader of DENX Software En ...
CVE-2018-1000205vulnerablevulnerablevulnerablevulnerableU-Boot contains a CWE-20: Improper Input Validation vulnerability in V ...
CVE-2018-18440vulnerablevulnerablevulnerablevulnerableDENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overf ...
CVE-2018-18439vulnerablevulnerablevulnerablevulnerableDENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer over ...
CVE-2017-3226vulnerablevulnerablevulnerablevulnerableDas U-Boot is a device bootloader that can read its configuration from ...
CVE-2017-3225vulnerablevulnerablevulnerablevulnerableDas U-Boot is a device bootloader that can read its configuration from ...

Resolved issues

BugDescription
CVE-2025-24857Improper access control for volatile memory containing boot code in Un ...
CVE-2024-57259sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-on ...
CVE-2024-57258Integer overflows in memory allocation in Das U-Boot before 2025.01-rc ...
CVE-2024-57257A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc ...
CVE-2024-57256An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.0 ...
CVE-2024-57255An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025. ...
CVE-2024-57254An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc ...
CVE-2022-34835In Das U-Boot through 2022.07-rc5, an integer signedness error and res ...
CVE-2022-33967squashfs filesystem implementation of U-Boot versions from v2020.10-rc ...
CVE-2022-33103Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an ...
CVE-2022-30790Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2 ...
CVE-2022-30767nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and throu ...
CVE-2022-30552Das U-Boot 2022.01 has a Buffer Overflow.
CVE-2022-2347There exists an unchecked length field in UBoot. The U-Boot DFU implem ...
CVE-2021-27138The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of uni ...
CVE-2021-27097The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified ...
CVE-2020-10648Das U-Boot through 2020.01 allows attackers to bypass verified boot re ...
CVE-2020-8432In Das U-Boot through 2020.01, a double free has been found in the cmd ...
CVE-2019-14204An issue was discovered in Das U-Boot through 2019.07. There is a stac ...
CVE-2019-14203An issue was discovered in Das U-Boot through 2019.07. There is a stac ...
CVE-2019-14202An issue was discovered in Das U-Boot through 2019.07. There is a stac ...
CVE-2019-14201An issue was discovered in Das U-Boot through 2019.07. There is a stac ...
CVE-2019-14200An issue was discovered in Das U-Boot through 2019.07. There is a stac ...
CVE-2019-14199An issue was discovered in Das U-Boot through 2019.07. There is an unb ...
CVE-2019-14198An issue was discovered in Das U-Boot through 2019.07. There is an unb ...
CVE-2019-14197An issue was discovered in Das U-Boot through 2019.07. There is a read ...
CVE-2019-14196An issue was discovered in Das U-Boot through 2019.07. There is an unb ...
CVE-2019-14195An issue was discovered in Das U-Boot through 2019.07. There is an unb ...
CVE-2019-14194An issue was discovered in Das U-Boot through 2019.07. There is an unb ...
CVE-2019-14193An issue was discovered in Das U-Boot through 2019.07. There is an unb ...
CVE-2019-14192An issue was discovered in Das U-Boot through 2019.07. There is an unb ...
CVE-2019-13106Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much ...
CVE-2019-13105Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a ...
CVE-2019-13104In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow c ...
CVE-2019-13103A crafted self-referential DOS partition table will cause all Das U-Bo ...
CVE-2019-11690gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 la ...
CVE-2019-11059Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit exte ...
CVE-2018-3968An exploitable vulnerability exists in the verified boot protection of ...

Security announcements

DSA / DLADescription
DLA-4642-1u-boot - security update
DLA-4320-1u-boot - security update
DLA-4150-1u-boot - security update

Search for package or bug name: Reporting problems