CVE Feed

    Dashboard / CVE / CVE-2024-42040

    CVE-2024-42040

    Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

    Published:Aug 23, 2024
    Last Modified:Apr 3, 2026
    EPS:Aug 23, 2024
    EPSS Score:0.0007
    CVSS Score:8.1

    Affected Products

    Vendor
    Denx
    Product
    U-boot

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High