barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directo…
Summary
barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry length values are non-zero. Attackers can supply a malicious ext4 filesystem image with a crafted directory entry containing a direntlen value of 0 to cause an infinite loop during directory listing or path resolution, resulting in the boot process hanging indefinitely.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://y637f9qq2x.com/posts/barebox-sandbox-vulns/
Sources
- NVD DATABASE
Original Links
- https://github.com/barebox/barebox Product
- https://github.com/barebox/barebox/releases/tag/v2026.04.0 Release Notes
- https://www.vulncheck.com/advisories/barebox-ext4-directory-parsing-infinite-loop-denial-of-service Third Party Advisory
- https://y637f9qq2x.com/posts/barebox-sandbox-vulns/
Timeline
- nvd_ingest NVD