CVE-2025-70290
Received Received - Intake

Integer Overflow in U-Boot ZFS Filesystem Support

Vulnerability report for CVE-2025-70290, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: MITRE

Description

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
denx uboot to 2026.04 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an integer overflow vulnerability in Denx U-Boot's ZFS filesystem support. It occurs when malformed on-disk metadata triggers incorrect memory allocation during the boot process. This can lead to out-of-bounds memory access, potentially causing a system crash or allowing arbitrary code execution.

Detection Guidance

Detection of this vulnerability requires checking the U-Boot version in use. If your system uses U-Boot before 2026.04, it may be vulnerable. Verify the version with 'strings /path/to/uboot | grep U-Boot' or 'uboot-version'. Ensure ZFS filesystem support is enabled and inspect metadata handling for malformed structures.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute arbitrary code during system boot, potentially gaining control over the device. It may also cause unexpected crashes, disrupting normal operations. Systems using affected U-Boot versions with ZFS support are at risk.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a low-level bootloader issue rather than data handling or privacy controls. Compliance impacts would depend on system-specific implementations and whether the vulnerability leads to unauthorized access or data breaches.

Mitigation Strategies

Update Denx U-Boot to version 2026.04 or later to address the integer overflow vulnerability in ZFS filesystem support.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-70290. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart