#bootloader
2 posts tagged #bootloader.
U-Boot TCP/NFS Vulnerabilities: Integer Underflow and Buffer Overflow in the World’s Most Popular Bootloader
Three CVEs in U-Boot’s network stack: one unchecked TCP header length that gives two reads past the packet, and an NFS path overflow past a 2048-byte buffer.
Four Vulnerabilities in barebox: From DHCP Parsing to EFI PE Loading
Four CVEs in barebox: an unbounded DHCP option scan, two ext4 parsing flaws, and a PE virtual-size integer overflow in the EFI loader.