CVE-2025-24857

EUVD-2025-202621
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.6 HIGH
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18.38%
Affected Products (NVD)
VendorProductVersion
denxu-boot
𝑥
< 2017.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
u-boot
bookworm
2023.01+dfsg-2+deb12u3
fixed
bookworm (security)
2023.01+dfsg-2+deb12u3
fixed
bullseye
2021.01+dfsg-5
fixed
bullseye (security)
2021.01+dfsg-5+deb11u3
fixed
forky
2025.01-3.2
fixed
sid
2025.01-3.2
fixed
trixie
2025.01-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
boot
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage