An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://gitlab.com/u-boot/u-boot | third party advisory |
https://blog.semmle.com/uboot-rce-nfs-vulnerability/ | third party advisory |