CVE-2026-15390
Received Received - Intake

U-Boot IP Reassembly State Not Cleared Leading to Arbitrary Code Execution

Vulnerability report for CVE-2026-15390, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: CERT.PL

Description

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
denx das_u-boot 2026.07
das_u-boot das_u-boot From 2009.08 (inc) to 2026.07 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-15390 is a vulnerability in Das U-Boot software where the system fails to clear IP reassembly state after delivering a complete datagram when CONFIG_IP_DEFRAG=y is enabled. This allows an attacker to send duplicated last-fragment IP packets to execute arbitrary code.

Detection Guidance

To detect this vulnerability, check if your Das U-Boot version is between 2009.08 and 2026.07 and has CONFIG_IP_DEFRAG=y enabled. Verify the version with commands like 'strings u-boot.bin | grep "U-Boot"' or 'strings u-boot.img | grep "U-Boot"' on the system. Monitor network traffic for duplicated last-fragment IP packets targeting the device.

Impact Analysis

An attacker could exploit this to execute arbitrary code on affected systems, potentially leading to unauthorized access, data breaches, or system compromise. Systems using Das U-Boot with CONFIG_IP_DEFRAG=y are at risk.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a technical flaw in Das U-Boot's IP reassembly mechanism that could allow arbitrary code execution via network traffic. Compliance impacts would depend on whether the affected system processes or stores regulated data, not the vulnerability itself.

Mitigation Strategies

Immediately upgrade Das U-Boot to version 2026.07 or later. If upgrading is not possible, disable CONFIG_IP_DEFRAG in the U-Boot configuration and rebuild the firmware. Apply network-level mitigations such as filtering fragmented IP packets at the network perimeter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15390. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart