U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection. | |
| Title | U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition Read | |
| First Time appeared |
Denx
Denx u-boot |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Denx
Denx u-boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T21:29:21.968Z
Reserved: 2026-08-08T16:43:04.178Z
Link: CVE-2026-71974
No data.
Status : Received
Published: 2026-09-29T22:18:22.250
Modified: 2026-09-29T22:18:22.250
Link: CVE-2026-71974
No data.
OpenCVE Enrichment
No data.
Weaknesses