An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://gitlab.com/u-boot/u-boot | third party advisory |
https://blog.semmle.com/uboot-rce-nfs-vulnerability/ | third party advisory |