Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field without any bounds check.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HPengutronix Barebox
APPPengutronix≤ 2020.05.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
Related vulnerabilities
CVE-2019-15937CRITICAL9.8PL ✓same product
Zdalny buffer overflow w Pengutronix Barebox — funkcja nfs_readlink_reply
CVE-2019-15938CRITICAL9.8PL ✓same product
Zdalny buffer overflow w Pengutronix Barebox — funkcja nfs_readlink_req
CVE-2026-34963HIGH8.6same product
barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi...
CVE-2026-34960HIGH7.1same product
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within ...
CVE-2026-33243HIGH8.2same product
barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding ...