U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-74221 | 8.2 HIGH | U-Boot 2026.10-rc5 之前 NFS READLINK 缓冲区溢出漏洞 |
| CVE-2026-74220 | 8.2 HIGH | U-Boot 2026.10-rc5 前 NFS 读取响应缓冲区溢出 |
| CVE-2026-71971 | 8.2 HIGH | U-Boot 2026.10-rc3 IP分片重组越界写漏洞 |
| CVE-2026-74225 | 7.1 HIGH | U-Boot 2026.10-rc5 之前 DHCPv6 越界写入漏洞 |
| CVE-2026-71972 | 5.9 MEDIUM | U-Boot 2026.10-rc5 BMP解码越界写漏洞 |
| CVE-2026-71973 | 5.2 MEDIUM | U-Boot 2026.10-rc4 SquashFS整数溢出漏洞 |
| CVE-2026-71974 | 4.8 MEDIUM | U-Boot Android Bootmeth越界写入漏洞 |
暂无评论