Product
high
advisory
U-Boot Use-After-Free in lwIP wget Implementation
1 TTP 1 CVEU-Boot versions prior to 2026.10-rc5 contain a use-after-free vulnerability in the httpc_recv_cb function, which can be triggered during failed HTTP data storage to cause a bootloader crash.
U-Boot
vulnerability
embedded-security
denial-of-service
1t
1c
high
threat
Buffer Overflow in U-Boot NFS Handling (CVE-2026-74221)
1 CVEA buffer overflow in the U-Boot nfs_readlink_reply function allows a malicious NFS server to trigger memory corruption via crafted READLINK replies.
exploited
U-Boot
1c
high
advisory
Out-of-Bounds Write Vulnerability in U-Boot IP Defragmentation
1 CVEAn out-of-bounds write vulnerability in the U-Boot __net_defragment() function allows remote attackers to corrupt memory and cause a denial-of-service during netboot operations.
U-Boot +1
vulnerability
bootloader
denial-of-service
1c