CVE-2026-34963
Last modified
CVE-2026-34963 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to validate that PointerToRawData plus copied size remains within the PE file buffer. An attacker can supply a malicious EFI PE binary via TFTP, USB, SD card, or network boot to trigger heap buffer overflow or out-of-bounds read from heap memory, potentially achieving code execution in bootloader context.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to validate that PointerToRawData plus copied size remains within the PE file buffer. An attacker can supply a malicious EFI PE binary via TFTP, USB, SD card, or network boot to trigger heap buffer overflow or out-of-bounds read from heap memory, potentially achieving code execution in bootloader context.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pengutronix | Barebox | < 2026.04.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-34963?
How severe is CVE-2026-34963?
How do I fix CVE-2026-34963?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34956A flaw was found in Open vSwitch. When Open vSwitch is confi…5.9
- CVE-2026-34959Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Fo…4.7
- CVE-2026-3496The JetBooking plugin for WordPress is vulnerable to SQL Inj…7.5
- CVE-2026-34960barebox prior to version 2026.04.0 contains an out-of-bounds…7.1
- CVE-2026-34961barebox prior to version 2026.04.0 contains out-of-bounds re…7.7
- CVE-2026-34962barebox version prior to 2026.04.0 contains a denial-of-serv…5.5
- CVE-2026-34964Adminer before 5.5.0 contains a server-side request forgery …5.8
- CVE-2026-34965Cockpit CMS contains an authenticated remote code execution …8.8
- CVE-2026-34966Gitea prior to 1.27.0 contains a server-side request forgery…7.6
- CVE-2026-34967Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin…5.4
- CVE-2026-34968Adminer before 5.4.3 contains an arbitrary file deletion vul…8.1
- CVE-2026-34969Nhost is an open source Firebase alternative with GraphQL. P…7.5
Are you affected by CVE-2026-34963?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
