ZeroHour

CVE-2020-8432

CVSS 3.1
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static analysis.

Vendors
denxopensuse
Products
u-boot, leap
Weakness
CWE-415, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.