PT-2026-39851 · Barebox · Barebox
Kazuma Matsumoto
·
Published
2026-05-11
·
Updated
2026-05-13
·
CVE-2026-34962
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
barebox versions prior to 2026.04.0
Description
A denial-of-service issue exists in the ext4 directory parsing within
fs/ext4/ext4 common.c. The ext4fs iterate dir() function does not validate that directory entry length values are non-zero. An attacker can provide a malicious ext4 filesystem image containing a crafted directory entry with a direntlen value of 0, triggering an infinite loop during path resolution or directory listing, which causes the boot process to hang indefinitely.Recommendations
Update to version 2026.04.0.
Fix
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Barebox