PT-2026-39869 · Barebox · Barebox

·

CVE-2026-34963

·

Published

2026-05-11

·

Updated

2026-05-12

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions barebox versions prior to 2026.04.0
Description Multiple memory-safety issues exist in the EFI PE loader within the efi/loader/pe.c file. An integer overflow occurs during virtual image size computation when using 32-bit arithmetic on section VirtualAddress and size values, leading to undersized heap allocation. Additionally, the PE section loading logic does not validate if PointerToRawData plus the copied size stays within the PE file buffer. An attacker can provide a malicious EFI PE binary through TFTP, USB, SD card, or network boot to trigger a heap buffer overflow or an out-of-bounds read from heap memory, which could allow code execution in the bootloader context.
Recommendations Update to version 2026.04.0.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34963

Affected Products

Barebox