Search CVE reports


Toggle filters

1 – 10 of 55 results


CVE-2026-15390

Medium priority
Needs evaluation

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment...

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2025-70292

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2025-70291

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2025-70293

Medium priority
Needs evaluation

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used...

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2025-70290

Medium priority
Needs evaluation

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by...

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-29009

Medium priority
Needs evaluation

U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff...

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-29008

Medium priority
Needs evaluation

U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet...

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-29007

Medium priority
Needs evaluation

U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious...

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-46728

Medium priority
Needs evaluation

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
u-boot-nezha Not in release Needs evaluation Needs evaluation — —
Show less packages

CVE-2025-45512

Medium priority
Vulnerable

A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.

2 affected packages

u-boot, u-boot-nezha

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
u-boot-nezha Not in release Vulnerable Vulnerable — —
Show less packages