LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2025-70293

Published
CVSS9.8
Severitycritical
WeaknessCWE-122
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-70293

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-70293.