U Boot

Vendor:

First CVE: Jun 26, 2018 · Active for 8 years

50
Total CVEs
More Total CVEs than 98% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact U Boot over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2018
8 years ago
Most Recent CVE
Jul 8, 2026
17 days ago

CVE Severity & Scoring

U Boot50 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local17 (34.0%)
Network23 (46.0%)
Unknown0 (0.0%)
Physical9 (18.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low46 (92.0%)
High4 (8.0%)
Unknown0 (0.0%)
User Interaction
None42 (84.0%)
Unknown0 (0.0%)
Required8 (16.0%)
Privileges Required
Low8 (16.0%)
High1 (2.0%)
None41 (82.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised N
Jul 8, 20269.840NONO
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
May 16, 20268.837NONO
U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootl
Jul 8, 20267.535NONO
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointe
Jun 30, 20229.832NONO
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this i
May 16, 20229.832NONO
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_in
Jul 31, 20199.832NONO
DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a
Nov 20, 20189.832NONO
In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an
Jan 29, 20209.831NONO
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply.
Jul 31, 20199.831NONO
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case.
Jul 31, 20199.831NONO

Exploit Exposure

Signals from CVEs in this product scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (50 CVEs).

Media Mentions

Signals from CVEs in this product scope (50 CVEs).

Top CNAs Publishing CVEs For U Boot

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2026.0447.70.4%00
2022.0748.71.3%00
2022.0417.80.5%00
2022.0137.50.5%00
2021.0437.80.8%00
2021.0117.80.5%00
2020.1017.80.5%00
2020.0117.81.4%00
2019.0747.61.2%00
2019.0417.10.4%00
2018.0928.81.3%00
2016.1119.81.9%00
2014.0717.00.3%00
2013.0717.00.3%00
1.1.316.50.3%00