U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader. | |
| Title | U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly | |
| First Time appeared |
Denx
Denx u-boot |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Denx
Denx u-boot |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T21:29:20.055Z
Reserved: 2026-08-08T16:43:04.178Z
Link: CVE-2026-71971
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses