Out-of-Bounds Memory Access in U-Boot Bootloader Allows Memory Corruption via DHCPv6
CVE-2026-74225
7.1HIGH
What is CVE-2026-74225?
A vulnerability in U-Boot versions prior to 2026.10-rc5 exists due to out-of-bounds memory access in the dhcp6_parse_options() function. This flaw results from inadequate validation of the lengths of the SERVERID and CLIENTID options from incoming DHCPv6 packets. Attackers with access to the local network can exploit this weakness by sending specially crafted DHCPv6 ADVERTISE or REPLY packets during the netboot process, leading to potential memory corruption and possibly crashing the bootloader.
Affected Version(s)
u-boot 0 < 2026.10-rc5
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Shahriyar Jalayeri (ByteRay Ltd.)
Mehrun P. Hunter (ByteRay Ltd.)
