Search CVE reports
1 – 10 of 63 results
U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment...
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |
[Unknown description]
2 affected packages
u-boot, u-boot-nezha
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| u-boot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| u-boot-nezha | Not in release | Needs evaluation | Needs evaluation | — | — |