<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>U-Boot (&lt; 2026.10-Rc5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/u-boot--2026.10-rc5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:30:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/u-boot--2026.10-rc5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>U-Boot Use-After-Free in lwIP wget Implementation</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-74222/</link><pubDate>Tue, 29 Sep 2026 22:30:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-74222/</guid><description>U-Boot versions prior to 2026.10-rc5 contain a use-after-free vulnerability in the httpc_recv_cb function, which can be triggered during failed HTTP data storage to cause a bootloader crash.</description><content:encoded><![CDATA[<p>U-Boot versions prior to 2026.10-rc5 contain a critical use-after-free vulnerability located within the httpc_recv_cb() function of the lwIP (lightweight IP) wget implementation. This flaw manifests when an HTTP data storage operation fails during the download process. In this failure state, the callback incorrectly frees the connection's Protocol Control Block (PCB) but proceeds to return an ERR_BUF status instead of the required ERR_ABRT. This discrepancy allows the TCP input path to subsequently reference the previously freed memory space, resulting in memory corruption and a hard crash of the bootloader. Because this occurs during the boot process, successful exploitation results in an immediate denial-of-service condition for the affected device.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to embedded systems utilizing U-Boot for network-based boot processes. If successfully triggered, the vulnerability results in a system-wide denial-of-service, as the device becomes unable to complete the boot sequence. This is particularly relevant for hardware platforms configured to perform automated firmware updates or netboot operations via the U-Boot lwIP stack.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade U-Boot to version 2026.10-rc5 or later to receive the patch for CVE-2026-74222.</li>
<li>Audit network-accessible boot configurations on embedded devices to restrict access to trusted internal management subnets.</li>
<li>If immediate patching is not possible, disable the network-based boot features or the wget functionality in the U-Boot environment until the firmware can be updated.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>embedded-security</category><category>denial-of-service</category></item><item><title>Buffer Overflow in U-Boot NFS Handling (CVE-2026-74221)</title><link>https://feed.craftedsignal.io/briefs/2026-09-u-boot-nfs-overflow/</link><pubDate>Tue, 29 Sep 2026 22:30:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-u-boot-nfs-overflow/</guid><description>A buffer overflow in the U-Boot nfs_readlink_reply function allows a malicious NFS server to trigger memory corruption via crafted READLINK replies.</description><content:encoded><![CDATA[<p>U-Boot versions prior to 2026.10-rc5 are vulnerable to a buffer overflow flaw in the nfs_readlink_reply() function located within net/nfs-common.c. This vulnerability is triggered when the bootloader processes responses from an NFS server during the network boot process. By providing a specially crafted NFS READLINK reply containing negative or oversized symlink length values, an attacker-controlled or compromised NFS server can cause memory corruption within the bootloader's execution environment. Successful exploitation may lead to a crash of the U-Boot process or potentially arbitrary code execution at the bootloader level. This is particularly relevant for embedded devices and systems that rely on network-based booting for deployment and maintenance.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to systems that perform network booting from untrusted or unauthenticated NFS sources. An attacker capable of positioning themselves as an NFS server can compromise the integrity of the device during its initial boot stage, potentially bypassing secure boot mechanisms or installing persistent malicious payloads before the operating system even loads. This can impact a wide array of IoT, industrial, and networking hardware that utilizes the U-Boot bootloader.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all U-Boot instances to version 2026.10-rc5 or later to address the vulnerable code in net/nfs-common.c. In environments where immediate patching is not possible, implement strict network segmentation to ensure the NFS boot server is isolated from untrusted traffic and restrict access to the NFS mount point to authorized, hardened infrastructure only.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item><item><title>Out-of-Bounds Write Vulnerability in U-Boot IP Defragmentation</title><link>https://feed.craftedsignal.io/briefs/2026-09-uboot-defrag-vuln/</link><pubDate>Tue, 29 Sep 2026 22:29:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-uboot-defrag-vuln/</guid><description>An out-of-bounds write vulnerability in the U-Boot __net_defragment() function allows remote attackers to corrupt memory and cause a denial-of-service during netboot operations.</description><content:encoded><![CDATA[<p>A memory corruption vulnerability, tracked as CVE-2026-71971, affects U-Boot versions prior to 2026.10-rc3 when the CONFIG_IP_DEFRAG feature is enabled. The flaw resides in the __net_defragment() function within net/net.c. During the network boot process, an attacker can transmit specially crafted IP fragments containing a non-zero offset and the More-Fragments flag. When processed by the bootloader, these fragments trigger an out-of-bounds write operation, leading to memory corruption. This vulnerability is significant for embedded environments utilizing network-based boot mechanisms, as successful exploitation results in an immediate crash of the bootloader, preventing the system from booting and effectively resulting in a permanent denial-of-service condition until manual recovery is performed on the affected hardware.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a severe risk to embedded systems that rely on U-Boot for network booting, such as networking equipment, industrial control systems, and IoT devices. Successful exploitation causes a complete bootloader failure, rendering devices unreachable and non-functional. Given that these devices often operate in headless or remote environments, the impact of such a denial-of-service event necessitates physical intervention to restore operational status, potentially causing widespread service disruption.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of embedded devices within the infrastructure that utilize U-Boot with the CONFIG_IP_DEFRAG feature enabled. Update all vulnerable firmware components to U-Boot version 2026.10-rc3 or later as soon as the upstream vendor releases patched builds. In environments where patching is not immediately feasible, restrict network access to the boot sequence by isolating systems that require network-based booting to trusted, physically secured management networks to mitigate the risk of remote fragment injection.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>bootloader</category><category>denial-of-service</category></item></channel></rss>