CVE-2025-24857 Affecting u-boot package, versions <2017.11+dfsg1-2


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-UBOOT-14545510
  • published22 Dec 2025
  • disclosed10 Dec 2025

Introduced: 10 Dec 2025

CVE-2025-24857  (opens in a new tab)

How to fix?

Upgrade Debian:unstable u-boot to version 2017.11+dfsg1-2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream u-boot package and not the u-boot package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.