Vulnerability Description
Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field without any bounds check.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pengutronix | Barebox | <= 2020.05.0 |
Related Weaknesses (CWE)
References
- https://git.pengutronix.de/cgit/barebox/commit/net/nfs.c?h=next&id=c0f0cbd1759a6PatchThird Party Advisory
- https://git.pengutronix.de/cgit/barebox/commit/net/nfs.c?h=next&id=c0f0cbd1759a6PatchThird Party Advisory
FAQ
What is CVE-2020-13910?
CVE-2020-13910 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field without any bounds chec...
How severe is CVE-2020-13910?
CVE-2020-13910 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-13910?
Check the references section above for vendor advisories and patch information. Affected products include: Pengutronix Barebox.