IP Reassembly Flaw in Das U-Boot Network Bootloader
CVE-2026-15390
9CRITICAL
What is CVE-2026-15390?
The Das U-Boot network bootloader contains a vulnerability that arises from the failure to clear the IP reassembly state after a complete datagram is delivered, particularly when the CONFIG_IP_DEFRAG=y parameter is set. This issue can be exploited by an attacker capable of sending fragmented IP traffic, enabling them to execute arbitrary code by transmitting duplicated last-fragment IP packets. A fix for this vulnerability has been implemented in version 2026.07.
Affected Version(s)
Das U-Boot 2009.08 <= 2026.07
