Junglewise Threat Intelligence

CVE-2019-14193: Das U-Boot stack overflow in nfs_readlink_reply

CVE-2019-14193 · Severity: critical · CVSS 9.8 · Published 2019-07-31

Technologies: Das U-Boot U-Boot, Siemens RUGGEDCOM ROX II. Vendors: Denx, Siemens.

Executive brief

A vulnerability exists in U-Boot, a widely used bootloader for embedded devices and industrial hardware. An attacker could exploit this flaw to execute unauthorized code or crash the device during the network booting process. This could lead to a complete takeover of the affected system, impacting operational availability and data integrity.

Technical details

A stack-based buffer overflow exists in the NFS (Network File System) implementation of Das U-Boot. The vulnerability is located in the 'nfs_readlink_reply' function, where an unbounded 'memcpy' operation occurs using an unvalidated length value after calculating a new path length. A remote attacker on the network could provide a specially crafted NFS reply to trigger this overflow. Successful exploitation could lead to arbitrary code execution or a denial-of-service condition during the boot phase. The issue is confirmed in versions through 2019.07 and has been addressed in downstream products like Siemens Ruggedcom Rox in version 2.17.1.

Affected products

  • Das U-Boot U-Boot through 2019.07
  • Siemens Corproation Ruggedcom Rox II family before 2.17.1

Timeline

  • 2019-07-31: disclosed
  • 2019-07-31: advisory: NVD publication date
  • 2026-05-12: patched: Siemens released patch for Ruggedcom Rox II family

References

Related threats