Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPengutronix Barebox
APPPengutronix≤ 2019.08.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
Related vulnerabilities
CVE-2020-13910CRITICAL9.1PL ✓same product
Barebox NFS: out-of-bounds read w net/nfs.c (nfs_read_reply)
CVE-2019-15937CRITICAL9.8PL ✓same product
Zdalny buffer overflow w Pengutronix Barebox — funkcja nfs_readlink_reply
CVE-2026-34963HIGH8.6same product
barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi...
CVE-2026-34960HIGH7.1same product
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within ...
CVE-2026-33243HIGH8.2same product
barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding ...