Skip to content
Threat Feed
high advisory

Out-of-Bounds Write Vulnerability in U-Boot IP Defragmentation

An out-of-bounds write vulnerability in the U-Boot __net_defragment() function allows remote attackers to corrupt memory and cause a denial-of-service during netboot operations.

CVE search metadata

CVE search record: CVE-2026-71971. Severity: high. CVSS: 8.2. KEV: no. Product: U-Boot (< 2026.10-rc3), U-Boot (< 2026.10-rc5). Brief: Out-of-Bounds Write Vulnerability in U-Boot IP Defragmentation. Brief link: https://feed.craftedsignal.io/briefs/2026-09-uboot-defrag-vuln/

What's new

  • 1. added coverage for U-Boot (< 2026.10-rc5) Sep 29, 22:30 via nvd

A memory corruption vulnerability, tracked as CVE-2026-71971, affects U-Boot versions prior to 2026.10-rc3 when the CONFIG_IP_DEFRAG feature is enabled. The flaw resides in the __net_defragment() function within net/net.c. During the network boot process, an attacker can transmit specially crafted IP fragments containing a non-zero offset and the More-Fragments flag. When processed by the bootloader, these fragments trigger an out-of-bounds write operation, leading to memory corruption. This vulnerability is significant for embedded environments utilizing network-based boot mechanisms, as successful exploitation results in an immediate crash of the bootloader, preventing the system from booting and effectively resulting in a permanent denial-of-service condition until manual recovery is performed on the affected hardware.

Impact

The vulnerability poses a severe risk to embedded systems that rely on U-Boot for network booting, such as networking equipment, industrial control systems, and IoT devices. Successful exploitation causes a complete bootloader failure, rendering devices unreachable and non-functional. Given that these devices often operate in headless or remote environments, the impact of such a denial-of-service event necessitates physical intervention to restore operational status, potentially causing widespread service disruption.

Recommendation

Prioritize the identification of embedded devices within the infrastructure that utilize U-Boot with the CONFIG_IP_DEFRAG feature enabled. Update all vulnerable firmware components to U-Boot version 2026.10-rc3 or later as soon as the upstream vendor releases patched builds. In environments where patching is not immediately feasible, restrict network access to the boot sequence by isolating systems that require network-based booting to trusted, physically secured management networks to mitigate the risk of remote fragment injection.

Mitigations

Update U-Boot firmware to version 2026.10-rc3 or later

immediate IT Operations

CVE-2026-71971