CVE-2020-8432

In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static analysis.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
denxu-boot
𝑥
≤ 2020.01
opensuseleap
15.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
u-boot
bookworm
2023.01+dfsg-2+deb12u1
fixed
bullseye
2021.01+dfsg-5
fixed
buster
ignored
jessie
ignored
sid
2024.01+dfsg-5
fixed
stretch
no-dsa
trixie
2024.01+dfsg-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
u-boot
bionic
Fixed 2020.10+dfsg-1ubuntu0~18.04.2
released
eoan
ignored
focal
Fixed 2021.01+dfsg-3ubuntu0~20.04.3
released
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
trusty
dne
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
u-boot-rpi3
suse enterprise desktop 15 SP1
2019.01-7.10.2
fixed
suse enterprise sap 12 SP5
2019.01-5.3.1
fixed
suse enterprise sap 15 SP1
2019.01-7.10.2
fixed
suse enterprise server 12 SP4
2018.03-4.3.1
fixed
suse enterprise server 12 SP5
2019.01-5.3.1
fixed
suse enterprise server 15
2018.03-4.6.2
fixed
suse enterprise server 15 SP1
2019.01-7.10.2
fixed
u-boot-rpiarm64
suse enterprise desktop 15 SP2
2020.01-10.9.1
fixed
suse enterprise desktop 15 SP3
2021.01-5.1
fixed
suse enterprise desktop 15 SP4
2021.10-150400.2.6
fixed
suse enterprise desktop 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise desktop 15 SP6
2021.10-150600.9.2
fixed
suse enterprise desktop 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise sap 15 SP2
2020.01-10.9.1
fixed
suse enterprise sap 15 SP3
2021.01-5.1
fixed
suse enterprise sap 15 SP4
2021.10-150400.2.6
fixed
suse enterprise sap 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise sap 15 SP6
2021.10-150600.9.2
fixed
suse enterprise sap 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise server 15 SP2
2020.01-10.9.1
fixed
suse enterprise server 15 SP3
2021.01-5.1
fixed
suse enterprise server 15 SP4
2021.10-150400.2.6
fixed
suse enterprise server 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise server 15 SP6
2021.10-150600.9.2
fixed
suse enterprise server 15 SP7
2021.10-150600.11.3.1
fixed
u-boot-rpiarm64-doc
suse enterprise desktop 15 SP2
2020.01-10.9.1
fixed
suse enterprise desktop 15 SP3
2021.01-5.1
fixed
suse enterprise desktop 15 SP4
2021.10-150400.2.6
fixed
suse enterprise desktop 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise desktop 15 SP6
2021.10-150600.9.2
fixed
suse enterprise desktop 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise sap 15 SP2
2020.01-10.9.1
fixed
suse enterprise sap 15 SP3
2021.01-5.1
fixed
suse enterprise sap 15 SP4
2021.10-150400.2.6
fixed
suse enterprise sap 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise sap 15 SP6
2021.10-150600.9.2
fixed
suse enterprise sap 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise server 15 SP2
2020.01-10.9.1
fixed
suse enterprise server 15 SP3
2021.01-5.1
fixed
suse enterprise server 15 SP4
2021.10-150400.2.6
fixed
suse enterprise server 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise server 15 SP6
2021.10-150600.9.2
fixed
suse enterprise server 15 SP7
2021.10-150600.11.3.1
fixed
u-boot-tools
suse enterprise desktop 15 SP1
2019.01-7.10.1
fixed
suse enterprise desktop 15 SP2
2020.01-10.9.1
fixed
suse enterprise desktop 15 SP3
2021.01-5.1
fixed
suse enterprise desktop 15 SP4
2021.10-150400.2.7
fixed
suse enterprise desktop 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise desktop 15 SP6
2021.10-150600.9.3
fixed
suse enterprise desktop 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise sap 12 SP5
2019.01-5.3.1
fixed
suse enterprise sap 15 SP1
2019.01-7.10.1
fixed
suse enterprise sap 15 SP2
2020.01-10.9.1
fixed
suse enterprise sap 15 SP3
2021.01-5.1
fixed
suse enterprise sap 15 SP4
2021.10-150400.2.7
fixed
suse enterprise sap 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise sap 15 SP6
2021.10-150600.9.3
fixed
suse enterprise sap 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise server 12 SP4
2018.03-4.3.1
fixed
suse enterprise server 12 SP5
2019.01-5.3.1
fixed
suse enterprise server 15
2018.03-4.6.1
fixed
suse enterprise server 15 SP1
2019.01-7.10.1
fixed
suse enterprise server 15 SP2
2020.01-10.9.1
fixed
suse enterprise server 15 SP3
2021.01-5.1
fixed
suse enterprise server 15 SP4
2021.10-150400.2.7
fixed
suse enterprise server 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise server 15 SP6
2021.10-150600.9.3
fixed
suse enterprise server 15 SP7
2021.10-150600.11.3.1
fixed