U-Boot U-Boot是U-Boot社区开源的一个免费、开源且可扩展的引导加载程序,适用于多种架构(ARM、MIPS、PowerPC、RISC-V、x86、x86_64),其目的是执行各种硬件初始化任务并启动设备的操作系统内核。 U-Boot 2026.04-rc3及之前版本存在缓冲区错误漏洞,该漏洞源于nfs_readlink_reply()函数存在缓冲区溢出,允许恶意或受攻击的NFS服务器通过返回多个相对符号链接目标(每个约1100字节)溢出2048字节的nfs_path_buff缓冲区,导致内存
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-29008 | 7.5 HIGH | U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine() |
| CVE-2026-29007 | 5.3 MEDIUM | U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c |
No comments yet