CVE-2019-13103

HIGH

denx/u-boot < 2019.04 - Denial of Service via Crafted DOS Partition Table

Title source: llm
STIX 2.1

Description

A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.

References (6)

Core 6

Scores

CVSS v3 7.1
EPSS 0.0040
EPSS Percentile 31.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-674
Status published
Products (3)
denx/u-boot 2019.04 (5 CPE variants)
denx/u-boot 2019.07 rc1 (4 CPE variants)
denx/u-boot < 2019.04
Published Jul 29, 2019
Tracked Since Feb 18, 2026