CVE-2026-34963Patch(pengutronix / barebox)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch pengutronix barebox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to validate that PointerToRawData plus copied size remains within the PE file buffer. An attacker can supply a malicious EFI PE binary via TFTP, USB, SD card, or network boot to trigger heap buffer overflow or out-of-bounds read from heap memory, potentially achieving code execution in bootloader context.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • barebox

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
barebox

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 105-1105-12
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-111
Patch1
2026-05-121
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34963 Memory Safety Vulnerabilities in barebox EFI PE Loader Prior to 2026.04.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34963

    Post summary

    The post announces a memory safety vulnerability in barebox EFI PE Loader before version 2026.04.0 (CVE-2026-34963) with no evidence of exploitation, PoC, or patch details.

    0000043
    4.0K followersView on X
  • Entity@0x2ed3bb60
    Patch

    🚨 CVE-2026-34963: barebox <2026.04.0 EFI PE loader integer overflow permits heap buffer overflow via malicious EFI binary. Code execution in bootloader context achievable. Patch immediately. https://0x2ed3bb60.xyz/threat/0d26e3355fe43872

    Post summary

    CVE‑2026‑34963 involves an integer overflow in barebox's EFI PE loader, enabling a heap buffer overflow and code execution in bootloader context. Patches are available and urgently recommended.

    0000029
    7 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppengutronixbarebox---

Explore more