Out-of-Bounds Memory Access in U-Boot Bootloader Allows Memory Corruption via DHCPv6
CVE-2026-74225

7.1HIGH

Key Information:

Vendor

U-boot

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-74225?

A vulnerability in U-Boot versions prior to 2026.10-rc5 exists due to out-of-bounds memory access in the dhcp6_parse_options() function. This flaw results from inadequate validation of the lengths of the SERVERID and CLIENTID options from incoming DHCPv6 packets. Attackers with access to the local network can exploit this weakness by sending specially crafted DHCPv6 ADVERTISE or REPLY packets during the netboot process, leading to potential memory corruption and possibly crashing the bootloader.

Affected Version(s)

u-boot 0 < 2026.10-rc5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shahriyar Jalayeri (ByteRay Ltd.)
Mehrun P. Hunter (ByteRay Ltd.)
.