Known Vulnerabilities for U-boot by Denx
Listed below are 10 of the newest known vulnerabilities associated with "U-boot" by "Denx".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-31788 | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xe... | Not Provided | 2026-03-25 | 2026-03-30 |
| CVE-2025-31733 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boot Div WP Sitemap wps... | Not Provided | 2025-04-01 | 2026-04-01 |
| CVE-2025-22551 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in albedo0 Boot-Modal boot... | Not Provided | 2025-01-07 | 2026-04-01 |
| CVE-2024-43028 | A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute ... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2024-40489 | There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attack... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2021-27138 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT. | 7.8 - HIGH | 2021-02-17 | 2021-02-24 |
| CVE-2021-27097 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. | 7.8 - HIGH | 2021-02-17 | 2021-02-23 |
| CVE-2020-10648 | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by pr... | 7.8 - HIGH | 2020-03-19 | 2021-03-26 |
| CVE-2020-8432 | In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing m... | 9.8 - CRITICAL | 2020-01-29 | 2023-11-07 |
| CVE-2019-13106 | Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which res... | 7.8 - HIGH | 2019-08-06 | 2023-03-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Denx | U-boot | 2021.04 | rc1 | All | All |
| Application | Denx | U-boot | 2021.04 | rc2 | All | All |
| Application | Denx | U-boot | 2021.01 | - | All | All |
| Application | Denx | U-boot | 2021.01 | rc1 | All | All |
| Application | Denx | U-boot | 2021.01 | rc2 | All | All |
| Application | Denx | U-boot | 2021.01 | rc3 | All | All |
| Application | Denx | U-boot | 2021.01 | rc4 | All | All |
| Application | Denx | U-boot | 2021.01 | rc5 | All | All |
| Application | Denx | U-boot | 2020.10 | - | All | All |
| Application | Denx | U-boot | 2020.10 | rc1 | All | All |
| Application | Denx | U-boot | 2020.10 | rc2 | All | All |
| Application | Denx | U-boot | 2020.10 | rc3 | All | All |
| Application | Denx | U-boot | 2020.10 | rc4 | All | All |
| Application | Denx | U-boot | 2020.10 | rc5 | All | All |
| Application | Denx | U-boot | 2020.07 | - | All | All |
| Application | Denx | U-boot | 2020.07 | rc1 | All | All |
| Application | Denx | U-boot | 2020.07 | rc2 | All | All |
| Application | Denx | U-boot | 2020.07 | rc3 | All | All |
| Application | Denx | U-boot | 2020.07 | rc4 | All | All |
| Application | Denx | U-boot | 2020.07 | rc5 | All | All |