#1149671 u-boot: CVE-2026-15390 CVE-2026-71971 CVE-2026-71972 CVE-2026-71973 CVE-2026-74220 CVE-2026-74221 CVE-2026-74225

Package:
src:u-boot
Source:
src:u-boot
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 07:07:02 UTC
Severity:
normal
Tags:
#1149671#5
Date:
2026-10-02 07:04:52 UTC
From:
To:
Hi,

The following vulnerabilities were published for u-boot.

CVE-2026-15390[0]:
| Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP
| reassembly state after delivering a complete datagram. An
| attacker who can deliver fragmented IP traffic can execute arbitrary
| code by sending duplicated last-fragment IP packets.   This issue
| was fixed in commit
| b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.


CVE-2026-71971[1]:
| U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an
| out-of-bounds write vulnerability in the __net_defragment() function
| in net/net.c. Remote attackers can send a crafted IP fragment with
| non-zero offset and More-Fragments flag set during netboot to
| corrupt adjacent memory and crash the bootloader.


CVE-2026-71972[2]:
| U-Boot through 2026.10-rc5 contains an out-of-bounds write
| vulnerability in the video_display_rle8_bitmap function in
| drivers/video/video_bmp.c. Attackers can supply a crafted
| RLE8-compressed BMP image to corrupt memory adjacent to the
| framebuffer and crash the bootloader.


CVE-2026-71973[3]:
| U-Boot before 2026.10-rc4 contains an integer overflow vulnerability
| in sqfs_read_directory_table() function when allocating the
| directory table buffer. Attackers can supply a crafted SquashFS
| image with an attacker-controlled superblock metablks_count value
| that causes heap buffer under-allocation and out-of-bounds writes,
| corrupting heap memory and crashing the bootloader.


CVE-2026-74220[4]:
| U-Boot before 2026.10-rc5 contains a buffer overflow in
| nfs_read_reply() function in net/nfs-common.c that allows attackers
| to corrupt memory by supplying crafted NFS READ reply lengths. A
| malicious NFS server can exploit signed integer handling to bypass
| length validation and write far past the destination buffer,
| crashing the bootloader or corrupting memory.


CVE-2026-74221[5]:
| U-Boot before 2026.10-rc5 contains a buffer overflow in
| nfs_readlink_reply() function in net/nfs-common.c when processing
| NFS server responses. A malicious NFS server can send crafted
| READLINK replies with negative or oversized symlink length values to
| corrupt memory and crash the bootloader.


CVE-2026-74225[6]:
| U-Boot before 2026.10-rc5 contains out-of-bounds memory access in
| dhcp6_parse_options() that fails to validate SERVERID and CLIENTID
| option lengths from DHCPv6 packets. Attackers on the local network
| can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to
| corrupt memory and crash the bootloader.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15390
https://www.cve.org/CVERecord?id=CVE-2026-15390
[1] https://security-tracker.debian.org/tracker/CVE-2026-71971
https://www.cve.org/CVERecord?id=CVE-2026-71971
[2] https://security-tracker.debian.org/tracker/CVE-2026-71972
https://www.cve.org/CVERecord?id=CVE-2026-71972
[3] https://security-tracker.debian.org/tracker/CVE-2026-71973
https://www.cve.org/CVERecord?id=CVE-2026-71973
[4] https://security-tracker.debian.org/tracker/CVE-2026-74220
https://www.cve.org/CVERecord?id=CVE-2026-74220
[5] https://security-tracker.debian.org/tracker/CVE-2026-74221
https://www.cve.org/CVERecord?id=CVE-2026-74221
[6] https://security-tracker.debian.org/tracker/CVE-2026-74225
https://www.cve.org/CVERecord?id=CVE-2026-74225

Regards,
Salvatore