logo

The power of variant analysis (Semmle QL) CVE-2019-15937 and CVE-2019-15938

ID: 83928597-b284-5ed8-9d60-0698c62f38ba

STIX ID: report--83928597-b284-5ed8-9d60-0698c62f38ba

Feed Name: SensePost Blog

Threat Score
50/100

Date Published: 2019-10-28

Date Updated: 2026-04-29

...
...

This tutorial-style report demonstrates using Semmle QL for variant analysis to locate two memory-corruption vulnerabilities in the Barebox bootloader where net_read_uint32 results were used unchecked as memcpy size parameters; the issues were reported, patched within days, and assigned CVE-2019-15937 and CVE-2019-15938. The post outlines query techniques (function call filtering, custom classes, and taint-tracking dataflow) and offers a challenge to detect similar assert-based size checks that may be removed in production builds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.