| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-74225 | vulnerable | vulnerable | vulnerable | vulnerable | U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp ... |
| CVE-2026-74221 | vulnerable | vulnerable | vulnerable | vulnerable | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_r ... |
| CVE-2026-74220 | vulnerable | vulnerable | vulnerable | vulnerable | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply ... |
| CVE-2026-71973 | vulnerable | vulnerable | vulnerable | vulnerable | U-Boot before 2026.10-rc4 contains an integer overflow vulnerability i ... |
| CVE-2026-71972 | vulnerable | vulnerable | vulnerable | vulnerable | U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerabili ... |
| CVE-2026-71971 | vulnerable | vulnerable | vulnerable | vulnerable | U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an ou ... |
| CVE-2026-29009 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in ... |
| CVE-2026-29008 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | U-Boot through 2026.04-rc3 contains an integer underflow vulnerability ... |
| CVE-2026-29007 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerabilit ... |
| CVE-2026-15390 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | Das U-Bootwith CONFIG_IP_DEFRAG=y parameter fails to clear IP reassemb ... |
| CVE-2025-70293 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | An issue was discovered in Denx U-Boot before 2026.04. An integer over ... |
| CVE-2025-70292 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | |
| CVE-2025-70291 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | |
| CVE-2025-70290 | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | An issue was discovered in Denx U-Boot before 2026.04. An integer over ... |
| Bug | Description |
|---|
| CVE-2026-74222 | U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in t ... |
| CVE-2026-71974 | U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerabilit ... |
| CVE-2026-46728 | Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verif ... |
| CVE-2025-24857 | Improper access control for volatile memory containing boot code in Un ... |
| CVE-2024-57259 | sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-on ... |
| CVE-2024-57258 | Integer overflows in memory allocation in Das U-Boot before 2025.01-rc ... |
| CVE-2024-57257 | A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc ... |
| CVE-2024-57256 | An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.0 ... |
| CVE-2024-57255 | An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025. ... |
| CVE-2024-57254 | An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc ... |
| CVE-2024-42040 | Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from ... |
| CVE-2022-34835 | In Das U-Boot through 2022.07-rc5, an integer signedness error and res ... |
| CVE-2022-33967 | squashfs filesystem implementation of U-Boot versions from v2020.10-rc ... |
| CVE-2022-33103 | Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an ... |
| CVE-2022-30790 | Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2 ... |
| CVE-2022-30767 | nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and throu ... |
| CVE-2022-30552 | Das U-Boot 2022.01 has a Buffer Overflow. |
| CVE-2022-2347 | There exists an unchecked length field in UBoot. The U-Boot DFU implem ... |
| CVE-2021-27138 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of uni ... |
| CVE-2021-27097 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified ... |
| CVE-2020-10648 | Das U-Boot through 2020.01 allows attackers to bypass verified boot re ... |
| CVE-2020-8432 | In Das U-Boot through 2020.01, a double free has been found in the cmd ... |
| CVE-2019-14204 | An issue was discovered in Das U-Boot through 2019.07. There is a stac ... |
| CVE-2019-14203 | An issue was discovered in Das U-Boot through 2019.07. There is a stac ... |
| CVE-2019-14202 | An issue was discovered in Das U-Boot through 2019.07. There is a stac ... |
| CVE-2019-14201 | An issue was discovered in Das U-Boot through 2019.07. There is a stac ... |
| CVE-2019-14200 | An issue was discovered in Das U-Boot through 2019.07. There is a stac ... |
| CVE-2019-14199 | An issue was discovered in Das U-Boot through 2019.07. There is an unb ... |
| CVE-2019-14198 | An issue was discovered in Das U-Boot through 2019.07. There is an unb ... |
| CVE-2019-14197 | An issue was discovered in Das U-Boot through 2019.07. There is a read ... |
| CVE-2019-14196 | An issue was discovered in Das U-Boot through 2019.07. There is an unb ... |
| CVE-2019-14195 | An issue was discovered in Das U-Boot through 2019.07. There is an unb ... |
| CVE-2019-14194 | An issue was discovered in Das U-Boot through 2019.07. There is an unb ... |
| CVE-2019-14193 | An issue was discovered in Das U-Boot through 2019.07. There is an unb ... |
| CVE-2019-14192 | An issue was discovered in Das U-Boot through 2019.07. There is an unb ... |
| CVE-2019-13106 | Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much ... |
| CVE-2019-13105 | Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a ... |
| CVE-2019-13104 | In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow c ... |
| CVE-2019-13103 | A crafted self-referential DOS partition table will cause all Das U-Bo ... |
| CVE-2019-11690 | gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 la ... |
| CVE-2019-11059 | Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit exte ... |
| CVE-2018-3968 | An exploitable vulnerability exists in the verified boot protection of ... |