GHSA-fm4f-g9jh-3qfqHighCVSS 8.2
U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function...
🔗 CVE IDs covered (1)
📋 Description
U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the bootloader.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-74222
- https://github.com/u-boot/u-boot/commit/2d94618a58aeb7630f18eee33419ce48d0fd3616
- https://github.com/u-boot/u-boot
- https://github.com/u-boot/u-boot/blob/v2026.07/net/lwip/wget.c#L194
- https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-use-after-free-in-lwip-wget-receive-callback
- https://github.com/advisories/GHSA-fm4f-g9jh-3qfq