GHSA-9gg4-qrm6-f795HighCVSS 8.2
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write...
🔗 CVE IDs covered (1)
📋 Description
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-71971
- https://github.com/u-boot/u-boot/commit/04ca915d5bf39dda5d1bce62d04d2b59d293c5b9
- https://github.com/u-boot/u-boot
- https://github.com/u-boot/u-boot/blob/v2026.07/net/net.c#L975
- https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-in-ip-fragment-reassembly
- https://github.com/advisories/GHSA-9gg4-qrm6-f795