{"id":"CVE-2021-37847","details":"crypto/digest.c in Pengutronix barebox through 2021.07.0 leaks timing information because memcmp is used during digest verification.","modified":"2026-07-09T00:21:04.384466Z","published":"2021-08-02T20:15:08.267Z","references":[{"type":"FIX","url":"https://github.com/saschahauer/barebox/commit/0a9f9a7410681e55362f8311537ebc7be9ad0fbe"},{"type":"EVIDENCE","url":"https://gist.github.com/gquere/816dfadbad98745090034100a8a651eb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/barebox/barebox","events":[{"introduced":"0"},{"last_affected":"72424fd057d135ec0e41139fe4cb5740471d33a5"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2021.07.0"}]}}],"versions":["v2021.07.0","v2021.06.0","v2021.05.0","v2021.03.0","v2021.02.0","v2021.01.0","v2020.12.0","v2020.11.0","v2020.10.0","v2020.09.0","v2020.08.0","v2020.07.0","v2020.06.0","v2020.05.0","v2020.04.0","v2020.03.0","v2020.02.0","v2020.01.0","v2019.12.0","v2019.11.0","v2019.10.0","v2019.09.0","v2019.08.0","v2019.07.0","v2019.06.0","v2019.05.0","v2019.04.0","v2019.03.0","v2019.02.0","v2019.01.0","v2018.12.0","v2018.11.0","v2018.10.0","v2018.09.0","v2018.08.0","v2018.07.0","v2018.06.0","v2018.05.0","v2018.04.0","v2018.03.0","v2018.02.0","v2018.01.0","v2017.12.0","v2017.11.0","v2017.10.0","v2017.09.0","v2017.08.0","v2017.07.0","v2017.06.0","v2017.05.0","v2017.04.0","v2017.03.0","v2017.02.0","v2017.01.0","v2016.11.0","v2016.10.0","v2016.08.0","v2016.09.0","v2016.07.0","v2016.06.0","v2016.05.0","v2016.04.0","v2016.03.0","v2016.02.0","v2016.01.0","v2015.12.0","v2015.11.0","v2015.10.0","v2015.09.0","v2015.08.0","v2015.07.0","v2015.06.0","v2015.05.0","v2015.04.0","v2015.03.0","v2015.02.0","v2015.01.0","v2014.12.0","v2014.11.0","v2014.10.0","v2014.09.0","v2014.08.0","v2014.07.0","v2014.06.0","v2014.05.0","v2014.04.0","v2014.03.0","v2014.02.0","v2014.01.0","v2013.12.0","v2013.11.0","v2013.10.0","v2013.09.0","v2013.08.0","v2013.07.0","v2013.06.0","v2013.05.0","v2013.04.0","v2013.03.0","v2013.02.0","v2013.01.0","v2012.12.0","v2012.11.0","v2012.10.0","v2012.09.0","v2012.08.0","v2012.07.0","v2012.06.0","v2012.05.0","v2012.04.0","v2012.03.0","v2012.02.0","v2012.01.0","v2011.12.0","v2011.11.0","v2011.10.0","v2011.09.0","v2011.08.0","v2011.07.0","v2011.06.0","v2011.05.0","v2011.04.0","v2011.03.0","v2011.02.0","v2011.01.0","v2010.12.0","v2010.11.0","v2010.10.0","v2010.09.0","v2010.08.0","v2010.07.0","v2010.06.0","v2010.05.0","v2010.04.0","v2010.03.0","v2010.02.0","v2009.12.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37847.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/saschahauer/barebox","events":[{"introduced":"0"},{"fixed":"0a9f9a7410681e55362f8311537ebc7be9ad0fbe"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37847.json","vanir_signatures_modified":"2026-07-09T00:21:04Z","vanir_signatures":[{"source":"https://github.com/saschahauer/barebox/commit/0a9f9a7410681e55362f8311537ebc7be9ad0fbe","target":{"file":"crypto/digest.c","function":"digest_generic_verify"},"deprecated":false,"digest":{"function_hash":"301584889156069090904562622525040506434","length":319},"id":"CVE-2021-37847-8199349f","signature_type":"Function","signature_version":"v1"},{"digest":{"line_hashes":["271334619018219239287410104355572862397","320835556679015987297444744653922937837","248201803692037093671842504412337342173","285480366245170309515497581774649101074","27282573744850338018709588609223000560","258290346364336418964311691047936510878","254309928623789668069109864278546826273","316172920102987295883885030603775344160","339271843571112485462380948539623857566"],"threshold":0.9},"id":"CVE-2021-37847-b9d9c9e4","signature_type":"Line","signature_version":"v1","source":"https://github.com/saschahauer/barebox/commit/0a9f9a7410681e55362f8311537ebc7be9ad0fbe","target":{"file":"crypto/digest.c"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}