Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 13 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pengutronix
Pengutronix barebox |
|
| CPEs | cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pengutronix
Pengutronix barebox |
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Barebox
Barebox barebox |
|
| Vendors & Products |
Barebox
Barebox barebox |
Mon, 11 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry length values are non-zero. Attackers can supply a malicious ext4 filesystem image with a crafted directory entry containing a direntlen value of 0 to cause an infinite loop during directory listing or path resolution, resulting in the boot process hanging indefinitely. | |
| Title | barebox ext4 Directory Parsing Infinite Loop Denial of Service | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-13T14:38:48.954Z
Reserved: 2026-03-31T17:58:43.754Z
Link: CVE-2026-34962
Updated: 2026-05-13T14:28:43.667Z
Status : Analyzed
Published: 2026-05-11T23:19:47.813
Modified: 2026-05-13T19:58:33.810
Link: CVE-2026-34962
No data.
OpenCVE Enrichment
Updated: 2026-05-12T00:15:07Z