U-Boot U-Boot是U-Boot社区开源的一个免费、开源且可扩展的引导加载程序,适用于多种架构(ARM、MIPS、PowerPC、RISC-V、x86、x86_64),其目的是执行各种硬件初始化任务并启动设备的操作系统内核。 U-Boot 2026.04-rc3及之前版本存在数字错误漏洞,该漏洞源于tcp_rx_state_machine()函数中存在整数下溢,网络邻近攻击者通过发送数据偏移字段被操纵的畸形TCP SYN+ACK数据包导致payload_len变为负数,从而引发引导加载程序崩溃并可
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-29009 | 8.2 HIGH | U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK |
| CVE-2026-29007 | 5.3 MEDIUM | U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c |
No comments yet