CVE Vulnerabilities

CVE-2018-3968

Improper Verification of Cryptographic Signature

Published: Mar 21, 2019 | Modified: Feb 02, 2023
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boots verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
U-boot Denx 2013.07 (including) 2014.07 (including)
U-boot Denx 2013.07-rc1 (including) 2013.07-rc1 (including)
U-boot Denx 2013.07-rc2 (including) 2013.07-rc2 (including)
U-boot Denx 2013.07-rc3 (including) 2013.07-rc3 (including)
U-boot Denx 2014.07-rc1 (including) 2014.07-rc1 (including)
U-boot Denx 2014.07-rc2 (including) 2014.07-rc2 (including)

References