CVE-2018-18440: Denx U-Boot

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.

Affected products

  • Denx U-Boot: up to and including 2018.07; version 2018.09 only

Published 2018-11-20. Last modified 2026-06-17.