VulnSea

pengutronix has 6 CVEs on record. The busiest recent month was May 2026 with 4. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. Most affected products: barebox (5), rauc (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
0 prev 5

Products

  • barebox 5
  • rauc 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

pengutronix vulnerabilities

CVEs affecting pengutronix, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-34963High· 8.4
4mo ago

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and siz…

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and siz…

Twilightpengutronix · bareboxEPSS 0.15%via NVD
CVE-2026-34962Medium· 6.2
4mo ago

barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry length values are non-zero

barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry length values are non-zero. A…

Sunlitpengutronix · bareboxEPSS 0.13%via NVD
CVE-2026-34961Medium· 6.2
4mo ago

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.c

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.c. Attackers can supply a malicious ex…

Sunlitpengutronix · bareboxEPSS 0.21%via NVD
CVE-2026-34960Medium· 6.5
4mo ago

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds. An attacker on…

Sunlitpengutronix · bareboxEPSS 0.25%via NVD
CVE-2026-34155Medium· 5.3
5mo ago

RAUC controls the update process on embedded Linux systems

RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only the fir…

Sunlitpengutronix · raucEPSS 0.14%via NVD
CVE-2026-33243High· 8.2
6mo ago

barebox is a bootloader

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booti…

Twilightpengutronix · bareboxEPSS 0.11%via NVD
pengutronix vulnerabilities (CVEs) · VulnSea