Executive brief
A vulnerability was found in U-Boot, a widely used bootloader for embedded devices and industrial hardware. An attacker could exploit this flaw to execute unauthorized code or crash the device during the network booting process. This could lead to a complete takeover of the affected hardware or a permanent service outage.
Technical details
An out-of-bounds write vulnerability exists in Das U-Boot through version 2019.07 due to an unbounded memcpy operation in the nfs_lookup_reply function. The issue stems from a failed or missing length check when processing NFS (Network File System) lookup replies over the network. A remote, unauthenticated attacker on the same network could provide a specially crafted NFS packet to trigger a buffer overflow. This can result in arbitrary code execution or a denial-of-service condition during the pre-boot environment. Patches have been integrated into later versions of U-Boot and downstream vendor firmware such as Siemens Ruggedcom Rox II.
Affected products
- Das U-Boot U-Boot through 2019.07
- Siemens Ruggedcom Rox II family before V2.17.1
Timeline
- 2019-07-31: disclosed
- 2019-07-31: advisory
- 2025-05-01: patched: Debian LTS update released
- 2026-05-12: patched: Siemens Ruggedcom Rox II update released