Security Advisory

CVE-2025-36938

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-11 19:35:51
Last updated 2026-03-11 15:07:48
Assigner Google_Devices
State PUBLISHED

Description

In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.