CVE-2026-74225

NameCVE-2026-74225
DescriptionU-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
u-boot (PTS)bookworm, bookworm (security)2023.01+dfsg-2+deb12u3vulnerable
trixie2025.01-3+deb13u1vulnerable
forky, sid2025.01-3.2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
u-bootsource(unstable)(unfixed)

Notes

Introduced with: https://github.com/u-boot/u-boot/commit/a0245818f7f8e375abc00f36ff88326331e4e2f9 (v2023.07-rc2)
Fixed by: https://github.com/u-boot/u-boot/commit/20209a62bc8565fc1e040882bc03c71ff0d73076 (v2026.10-rc5)

Search for package or bug name: Reporting problems