U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader. | |
| Title | U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation | |
| First Time appeared |
Denx
Denx u-boot |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Denx
Denx u-boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T21:29:21.349Z
Reserved: 2026-08-08T16:43:04.178Z
Link: CVE-2026-71973
No data.
Status : Received
Published: 2026-09-29T22:18:22.080
Modified: 2026-09-29T22:18:22.080
Link: CVE-2026-71973
No data.
OpenCVE Enrichment
No data.
Weaknesses