CVE-2021-27097

Name
CVE-2021-27097
Description
The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/u-boot/u-boot/commit/6f3c2d8aa5e6cbd80b5e869bbbddecb66c329d01
Patch https://github.com/u-boot/u-boot/commit/b6f4c757959f8850e1299a77c8e5713da78e8ec0
Patch https://github.com/u-boot/u-boot/commit/8a7d4cf9820ea16fabd25a6379351b4dc291204b

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* u-boot >= None <= 2021.01
cpe:2.3:a:denx:u-boot:2021.04:rc1:*:*:*:*:*:* u-boot == None == 2021.04

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
u-boot 3.14-main 2021.04-r0 Milan P. Stanić <mps@arvanta.net> fixed