📦 U Boot

by Denx

🔍 What is U Boot?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-34835

CRITICAL CVSS 9.8 Jun 30, 2022

CVE-2022-34835 is a critical stack-based buffer overflow vulnerability in Das U-Boot bootloader's 'i2c md' command. An attacker with access to the bootloader console can exploit this to execute arbitr...

CVE-2022-30767

CRITICAL CVSS 9.8 May 16, 2022

This vulnerability is a buffer overflow in Das U-Boot's NFS client implementation that allows remote code execution. It affects systems using U-Boot with NFS support enabled, particularly embedded dev...

CVE-2025-24857

HIGH CVSS 7.6 Dec 10, 2025

This vulnerability allows attackers to bypass access controls in U-Boot bootloader's volatile memory, potentially executing arbitrary code during system boot. It affects devices using U-Boot versions ...

CVE-2024-57254

HIGH CVSS 7.1 Feb 18, 2025

An integer overflow vulnerability in Das U-Boot's squashfs filesystem parser allows attackers to cause memory corruption via specially crafted symlink entries. This affects systems using U-Boot bootlo...

CVE-2024-57255

HIGH CVSS 7.1 Feb 18, 2025

This CVE describes an integer overflow vulnerability in Das U-Boot's squashfs filesystem handling. When processing a specially crafted squashfs filesystem with a specific inode size, it causes a zero-...

CVE-2024-57258

HIGH CVSS 7.1 Feb 18, 2025

Integer overflow vulnerabilities in Das U-Boot's memory allocation functions allow attackers to cause heap corruption via specially crafted squashfs filesystems. This affects systems using U-Boot boot...

CVE-2024-57259

HIGH CVSS 7.1 Feb 18, 2025

An off-by-one error in Das U-Boot's squashfs directory listing function (sqfs_search_dir) causes heap memory corruption when processing paths. This vulnerability affects systems using Das U-Boot bootl...

CVE-2025-45512

MEDIUM CVSS 6.5 Aug 5, 2025

This vulnerability in U-Boot v1.1.3 allows attackers to bypass signature verification during firmware updates, enabling installation of malicious firmware that can execute arbitrary code. It affects s...