CVE-2026-71974

NameCVE-2026-71974
DescriptionU-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
u-boot (PTS)bookworm, bookworm (security)2023.01+dfsg-2+deb12u3fixed
trixie2025.01-3+deb13u1fixed
forky, sid2025.01-3.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
u-bootsource(unstable)(not affected)

Notes

- u-boot <not-affected> (Vulnerable code introduced later)
Introduced with: https://github.com/u-boot/u-boot/commit/abadcda24b100b8eb0f138085cca6595518cec85 (v2025.04-rc1)
Fixed by: https://github.com/u-boot/u-boot/commit/35432ef6fe2c79ab72709966e64815a45eb55c76 (v2026.10-rc3)

Search for package or bug name: Reporting problems