CVE-2019-11690
Dashboard / Vulnerabilities / CVE-2019-11690
CVE-2019-11690
Published: 3 May 2019Last Modified: 8 Jul 2026
Summary:
Details: gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.
References: https://patchwork.ozlabs.org/patch/1092945
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- dda0dbfc69f3d560c87f5be85f127ed862ea6721
Fixed -None
Affected versions
v2019.04
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
