DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.
{ "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-amlogic" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-exynos" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-imx" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-omap" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-qcom" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-rockchip" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-rpi" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-sunxi" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-tegra" }, { "binary_version": "2019.07+dfsg-1ubuntu4~18.04.1", "binary_name": "u-boot-tools" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-amlogic" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-exynos" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-imx" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-mvebu" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-omap" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-qcom" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-rockchip" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-rpi" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-sunxi" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-tegra" }, { "binary_version": "2019.07+dfsg-1ubuntu6", "binary_name": "u-boot-tools" } ], "availability": "No subscription required" }