Debian alert DLA-4642-1 (u-boot)
| From: | Andreas Henriksson <andreas@fatal.se> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4642-1] u-boot security update | |
| Date: | Tue, 23 Jun 2026 23:22:42 +0200 | |
| Message-ID: | <nqpnswecb2pzzw5xxnijkdsethqq6dzzfttqok6zuuya4tqy2u@vot7h4qfvszl> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4642-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson June 23, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : u-boot Version : 2021.01+dfsg-5+deb11u3 2023.01+dfsg-2+deb12u3 CVE ID : CVE-2024-42040 CVE-2026-46728 Debian Bug : 1081557 1136954 Multiple issues where found in u-boot, a cross-platform bootloader for embedded systems, which could lead to information leak and signature verification bypass. CVE-2024-42040 buffer overread vulnerability in the DHCP implementation CVE-2026-46728 mishandles use of unit addresses in a FIT For Debian 11 bullseye, these problems have been fixed in version 2021.01+dfsg-5+deb11u3. For Debian 12 bookworm, these problems have been fixed in version 2023.01+dfsg-2+deb12u3. We recommend that you upgrade your u-boot packages. For the detailed security status of u-boot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/u-boot Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmo6+SAACgkQC8R9xk0T UwYV9g/9FIDGuaWbnOqEg9rlCYzcY6JDMKQbmJZdJe4nm5Dc0YVJWpPhw0oIqHUm XC/ZuAStKJc3pwMN8aTAUWzyjPH/DZtKFSvx130n1Ht0TaPRcxL6mg/q1hjyy4Ul x0+ljjVsaOPzhf5ZMAcByxCzuoE7HjxMwaay/sMEZSbrp+QlwHsD2uH1Gz6y90/d 1Jbte9BObVgqVUfBUob7Ozbvyu3v8rNJYWwQ8w3XERSzhbxWoyShifFmfuNW2D8P xowG2xWsDzIUfxhWa9021hCfIjJ/NPl1Kw6M85JjdpEJQ8FnPOlLCGJgCz6f1QJO QDEb669JxH1kS9f3rCNMXzeobUAH2k3HjFjLGQUQOo8dVC2S8s8defy3bl+wnOZ3 9lCFQT1E6qTZfVbLjxhUpI5t7l5dZweQ+72ulGL7FCm6c9sLjI+owCJp4JSnS8T0 plZvLlaXjXQqxLtiSOh6t4QMkwNGIi01jYcoEhUTSFdthVZUfPV6XcIumTJ97UrF oUBuAjiRzZZVn792Qbbz0Y2TmHqUlIKJ4fe9QbpCm7hlQrrUXCwUjc011zO5QOPl 0TAFd8e1sLCKlVLNwUW7Pw4k0xSR+1PZWmi3IBubdsOz945XDjzZGIfKXwzWEh93 OXRAYx5DneEJhyBq4A3Oz8rzgPV+w65rTKPgeDxRd/7t2S5MHCw= =ee6x -----END PGP SIGNATURE-----
