Buffer Overflow Vulnerability in U-Boot Bootloader Affecting U-Boot Users
CVE-2026-74220

8.8HIGH

Key Information:

Vendor

U-boot

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-74220?

U-Boot Bootloader prior to version 2026.10-rc5 is susceptible to a buffer overflow in the nfs_read_reply() function, located in net/nfs-common.c. This vulnerability arises when an attacker manipulates the response from a malicious NFS server, exploiting weak signed integer handling to bypass length validation. By providing crafted NFS READ reply lengths, attackers can overwrite memory beyond the designated buffer, leading to potential system crashes or memory corruption, jeopardizing the integrity and stability of affected systems.

Affected Version(s)

u-boot 0 < 2026.10-rc5

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shahriyar Jalayeri (ByteRay Ltd.)
Mehrun P. Hunter (ByteRay Ltd.)
.