Candidate: CVE-2018-3968 PublicDate: 2019-03-21 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3968 https://talosintelligence.com/vulnerability_reports/TALOS-2018-0633 Description: An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.0 HIGH] Patches_u-boot: upstream_u-boot: released (2014.07+dfsg1-1) precise/esm_u-boot: DNE trusty_u-boot: ignored (out of standard support) trusty/esm_u-boot: DNE xenial_u-boot: not-affected (2014.07+dfsg1-1) esm-infra/xenial_u-boot: not-affected (2014.07+dfsg1-1) bionic_u-boot: not-affected (2019.07+dfsg-1ubuntu4~18.04.1) focal_u-boot: not-affected devel_u-boot: not-affected