Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15390— Out-of-bounds write in Das U-Boot

Quick assessment

Affected
DENX Software Engineering Das U-Boot
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

当 U-Boot 配置了 参数时,在成功重组并交付完整的 IP 数据报后,未能清除 IP 重组状态。能够发送分片 IP 流量的攻击者,可以通过发送重复的最后一个分片(last-fragment)IP 数据包来执行任意代码。 该问题已在版本 2026.07 中通过提交 b1aec609bb5e0d08c25c888c91935287ab4ee5fa 修复。

CVSS 9.0 · Critical

Possible ATT&CK Techniques 1 AI

T1059.004 · Unix Shell
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15390

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds write in Das U-Boot
Source: CVE Program / CVE List V5
Vulnerability Description
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
DENX Software Engineering Das U-Boot 2009.08 ~ 2026.07 -

II. Public POCs for CVE-2026-15390

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15390

请登录查看更多情报信息。

Other References for CVE-2026-15390 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15390

No comments yet


Leave a comment