<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Das U-Boot - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/das-u-boot/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:30:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/das-u-boot/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>U-Boot Use-After-Free in lwIP wget Implementation</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-74222/</link><pubDate>Tue, 29 Sep 2026 22:30:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-74222/</guid><description>U-Boot versions prior to 2026.10-rc5 contain a use-after-free vulnerability in the httpc_recv_cb function, which can be triggered during failed HTTP data storage to cause a bootloader crash.</description><content:encoded><![CDATA[<p>U-Boot versions prior to 2026.10-rc5 contain a critical use-after-free vulnerability located within the httpc_recv_cb() function of the lwIP (lightweight IP) wget implementation. This flaw manifests when an HTTP data storage operation fails during the download process. In this failure state, the callback incorrectly frees the connection's Protocol Control Block (PCB) but proceeds to return an ERR_BUF status instead of the required ERR_ABRT. This discrepancy allows the TCP input path to subsequently reference the previously freed memory space, resulting in memory corruption and a hard crash of the bootloader. Because this occurs during the boot process, successful exploitation results in an immediate denial-of-service condition for the affected device.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to embedded systems utilizing U-Boot for network-based boot processes. If successfully triggered, the vulnerability results in a system-wide denial-of-service, as the device becomes unable to complete the boot sequence. This is particularly relevant for hardware platforms configured to perform automated firmware updates or netboot operations via the U-Boot lwIP stack.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade U-Boot to version 2026.10-rc5 or later to receive the patch for CVE-2026-74222.</li>
<li>Audit network-accessible boot configurations on embedded devices to restrict access to trusted internal management subnets.</li>
<li>If immediate patching is not possible, disable the network-based boot features or the wget functionality in the U-Boot environment until the firmware can be updated.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>embedded-security</category><category>denial-of-service</category></item></channel></rss>