{"id":"CVE-2019-15938","details":"Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.","modified":"2026-07-08T16:08:15.490474Z","published":"2019-09-05T15:15:12.843Z","references":[{"type":"FIX","url":"https://git.pengutronix.de/cgit/barebox/commit/fs/nfs.c?h=next&id=574ce994016107ad8ab0f845a785f28d7eaa5208"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/barebox/barebox","events":[{"introduced":"0"},{"last_affected":"4e105e882aec0edc0d8c8904f755b024be4c6c2f"}],"database_specific":{"cpe":"cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2019.08.1"}],"source":"CPE_RANGE"}}],"versions":["v2019.08.1","v2019.08.0","v2019.07.0","v2019.06.0","v2019.05.0","v2019.04.0","v2019.03.0","v2019.02.0","v2019.01.0","v2018.12.0","v2018.11.0","v2018.10.0","v2018.09.0","v2018.08.0","v2018.07.0","v2018.06.0","v2018.05.0","v2018.04.0","v2018.03.0","v2018.02.0","v2018.01.0","v2017.12.0","v2017.11.0","v2017.10.0","v2017.09.0","v2017.08.0","v2017.07.0","v2017.06.0","v2017.05.0","v2017.04.0","v2017.03.0","v2017.02.0","v2017.01.0","v2016.11.0","v2016.10.0","v2016.08.0","v2016.09.0","v2016.07.0","v2016.06.0","v2016.05.0","v2016.04.0","v2016.03.0","v2016.02.0","v2016.01.0","v2015.12.0","v2015.11.0","v2015.10.0","v2015.09.0","v2015.08.0","v2015.07.0","v2015.06.0","v2015.05.0","v2015.04.0","v2015.03.0","v2015.02.0","v2015.01.0","v2014.12.0","v2014.11.0","v2014.10.0","v2014.09.0","v2014.08.0","v2014.07.0","v2014.06.0","v2014.05.0","v2014.04.0","v2014.03.0","v2014.02.0","v2014.01.0","v2013.12.0","v2013.11.0","v2013.10.0","v2013.09.0","v2013.08.0","v2013.07.0","v2013.06.0","v2013.05.0","v2013.04.0","v2013.03.0","v2013.02.0","v2013.01.0","v2012.12.0","v2012.11.0","v2012.10.0","v2012.09.0","v2012.08.0","v2012.07.0","v2012.06.0","v2012.05.0","v2012.04.0","v2012.03.0","v2012.02.0","v2012.01.0","v2011.12.0","v2011.11.0","v2011.10.0","v2011.09.0","v2011.08.0","v2011.07.0","v2011.06.0","v2011.05.0","v2011.04.0","v2011.03.0","v2011.02.0","v2011.01.0","v2010.12.0","v2010.11.0","v2010.10.0","v2010.09.0","v2010.08.0","v2010.07.0","v2010.06.0","v2010.05.0","v2010.04.0","v2010.03.0","v2010.02.0","v2009.12.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15938.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}