Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Denx U-bootAI | 29/9/2026 | 30/9/2026 | U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader. | |
| Pendiente de análisis | Alta (8.8) | 0.30% | — | Denx U-bootAI | 29/9/2026 | 2/10/2026 | U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the… | |
| Pendiente de análisis | Alta (8.8) | 0.34% | — | Denx U-bootAI | 29/9/2026 | 30/9/2026 | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader. | |
| Pendiente de análisis | Alta (8.8) | 0.34% | — | Denx U BootAI | 29/9/2026 | 30/9/2026 | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer,… | |
| Pendiente de análisis | Media (4.3) | 0.18% | — | Denx U-bootAI | 29/9/2026 | 30/9/2026 | U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without… | |
| Pendiente de análisis | Media (5.2) | 0.18% | — | Denx U-bootAI | 29/9/2026 | 2/10/2026 | U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds… | |
| Pendiente de análisis | Media (6) | 0.22% | — | Denx U-bootAI | 29/9/2026 | 30/9/2026 | U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader. | |
| Pendiente de análisis | Alta (8.8) | 0.38% | — | Denx U-bootAI | 29/9/2026 | 30/9/2026 | U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader. | |
| Pendiente de análisis | Crítica (9) | 0.29% | — | Denx U-bootAI | 29/9/2026 | 30/9/2026 | Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in… | |
| Aplazada | Crítica (9.8) | 0.82% | — | Denx U-bootAI | 26/8/2026 | 9/9/2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Denx U-bootAI | 26/8/2026 | 9/9/2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution… | |
| Modificada | Alta (8.8) | 0.74% | — | Denx U-boot | 8/7/2026 | 24/7/2026 | U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative… | |
| Analizada | Alta (8.7) | 0.71% | — | Denx U-boot | 8/7/2026 | 22/7/2026 | U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the… | |
| Analizada | Media (6.9) | 0.67% | — | Denx U-boot | 8/7/2026 | 22/7/2026 | U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a… | |
| Aplazada | Media (6.8) | 0.29% | — | Gncc GP5AIDenx U-bootAI | 4/6/2026 | 22/7/2026 | An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments. | |
| Analizada | Alta (8.8) | 0.13% | — | Denx U-boot | 16/5/2026 | 11/9/2026 | Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash. | |
| Analizada | Alta (7.6) | 0.27% | — | Denx U-boot | 10/12/2025 | 17/6/2026 | Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code. | |
| Analizada | Media (6.5) | 0.33% | — | Denx U-boot | 5/8/2025 | 17/6/2026 | A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution. | |
| Modificada | Media (6.8) | 0.37% | — | Denx U-boot | 18/2/2025 | 17/6/2026 | sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation. | |
| Modificada | Alta (7.8) | 0.25% | — | Denx U-boot | 18/2/2025 | 17/6/2026 | Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64. | |
| Modificada | Baja (2.4) | 0.32% | — | Denx U-boot | 18/2/2025 | 17/6/2026 | A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting. | |
| Modificada | Media (6.8) | 0.37% | — | Denx U-boot | 18/2/2025 | 17/6/2026 | An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite. | |
| Modificada | Media (6.8) | 0.36% | — | Denx U-boot | 18/2/2025 | 17/6/2026 | An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite. | |
| Modificada | Media (6.8) | 0.36% | — | Denx U-boot | 18/2/2025 | 17/6/2026 | An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem. | |
| Analizada | Alta (8.1) | 0.60% | — | Denx U-boot | 23/8/2024 | 17/6/2026 | Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters… |