PT-2026-82241 · Debian+1 · U-Boot+1

CVE-2025-70293

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Denx U-Boot versions prior to 2026.04
Description An integer overflow occurs in the ext4fs get bgdtable() function. The size calculation can result in an under-allocated buffer, which is subsequently used in memcpy(). This flaw may lead to arbitrary code execution, a denial of service, or other unspecified impacts.
Recommendations Update Denx U-Boot to version 2026.04 or later. As a temporary workaround, consider restricting the use of the ext4fs get bgdtable() function until the update is applied.

Fix

Heap Based Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70293

Affected Products

U-Boot
U-Boot-Nezha