In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static analysis.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade u-boot | Jul 30, 2024 | Jan 29, 2020 |
| Gentoo Linux | — | Upgrade dev-embedded/u-boot-tools. | May 10, 2024 | Jan 29, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade uboot-tools-help | Nov 12, 2021 | Jan 29, 2020 |
| Suse | — | Upgrade u-boot-toolsUpgrade u-boot-rpiarm64-docUpgrade u-boot-rpiarm64Upgrade u-boot-rpi3 | Nov 8, 2020 | Jan 29, 2020 |
| Ubuntu | — | Upgrade u-boot | Nov 19, 2024 | Jan 29, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub