CVE-2024-42040

EUVD-2024-39870
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46.28%
Affected Products (NVD)
VendorProductVersion
denxu-boot
𝑥
≤ 2025.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
u-boot
bookworm
postponed
bullseye
postponed
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
u-boot
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
oracular
ignored
plucky
ignored
questing
ignored
resolute
deferred
xenial
deferred
u-boot-nezha
focal
dne
jammy
deferred
noble
deferred
oracular
ignored
plucky
ignored
questing
dne
resolute
dne