U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during ne
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74222 | 8.2 HIGH | U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback |
| CVE-2026-74221 | 8.2 HIGH | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK |
| CVE-2026-74220 | 8.2 HIGH | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply |
| CVE-2026-71971 | 8.2 HIGH | U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly |
| CVE-2026-71972 | 5.9 MEDIUM | U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder |
| CVE-2026-71973 | 5.2 MEDIUM | U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation |
| CVE-2026-71974 | 4.8 MEDIUM | U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition Read |
No comments yet