HIGH 8.8 NVD
CVE-2026-71971
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote at
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
References
- https://github.com/u-boot/u-boot
- https://github.com/u-boot/u-boot/blob/v2026.07/net/net.c#L975
- https://github.com/u-boot/u-boot/commit/04ca915d5bf39dda5d1bce62d04d2b59d293c5b9
- https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-in-ip-f
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.