IP Reassembly Flaw in Das U-Boot Network Bootloader
CVE-2026-15390

9CRITICAL

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-15390?

The Das U-Boot network bootloader contains a vulnerability that arises from the failure to clear the IP reassembly state after a complete datagram is delivered, particularly when the CONFIG_IP_DEFRAG=y parameter is set. This issue can be exploited by an attacker capable of sending fragmented IP traffic, enabling them to execute arbitrary code by transmitting duplicated last-fragment IP packets. A fix for this vulnerability has been implemented in version 2026.07.

Affected Version(s)

Das U-Boot 2009.08 <= 2026.07

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mateusz Furdyna, Nokia
.