Source: u-boot Version: 2025.01-3.2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for u-boot. CVE-2025-70290[0]: | An issue was discovered in Denx U-Boot before 2026.04. An integer | overflow vulnerability in the ZFS filesystem support can be | triggered by malformed on-disk metadata. The issue may result in | incorrect memory allocation followed by out-of-bounds memory access, | potentially leading to a crash or arbitrary code execution during | the boot process. CVE-2025-70291[1], CVE-2025-70292[2], and CVE-2025-70293[3]: | An issue was discovered in Denx U-Boot before 2026.04. An integer | overflow vulnerability exists in function ext4fs_get_bgdtable, the | size calculation can lead to under allocation and this | underallocated buffer will be used in memcpy() which could lead to | arbitrary code execution, a denial of service, or other unspecified | impacts. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-70290 https://www.cve.org/CVERecord?id=CVE-2025-70290 [1] https://security-tracker.debian.org/tracker/CVE-2025-70291 https://www.cve.org/CVERecord?id=CVE-2025-70291 [2] https://security-tracker.debian.org/tracker/CVE-2025-70292 https://www.cve.org/CVERecord?id=CVE-2025-70292 [3] https://security-tracker.debian.org/tracker/CVE-2025-70293 https://www.cve.org/CVERecord?id=CVE-2025-70293 Regards, Salvatore

