CVE-2025-70290

NameCVE-2025-70290
DescriptionAn issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1146625

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
u-boot (PTS)bookworm, bookworm (security)2023.01+dfsg-2+deb12u3vulnerable
trixie2025.01-3+deb13u1vulnerable
forky, sid2025.01-3.2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
u-bootsource(unstable)(unfixed)1146625

Notes

[trixie] - u-boot <no-dsa> (Minor issue)
https://www.openwall.com/lists/oss-security/2026/08/28/4
https://source.denx.de/u-boot/u-boot/-/commit/c8f0294285f6588322363e1711bc57118e6fc9a3 (v2026.04-rc1)

Search for package or bug name: Reporting problems