Vendor
U-Boot versions prior to 2026.10-rc5 contain a use-after-free vulnerability in the httpc_recv_cb function, which can be triggered during failed HTTP data storage to cause a bootloader crash.