CVE-2026-74221
Received Received - Intake

Buffer Overflow in U-Boot Bootloader via NFS READLINK

Vulnerability report for CVE-2026-74221, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
denx uboot to 2026.10-rc5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-195 The product uses a signed primitive and performs a cast to an unsigned primitive, which can produce an unexpected value if the value of the signed primitive can not be represented using an unsigned primitive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in U-Boot's nfs_readlink_reply() function in net/nfs-common.c. It occurs when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values, leading to memory corruption and bootloader crashes.

Detection Guidance

This vulnerability can be detected by checking the U-Boot version on your system. If it is before 2026.10-rc5, it is vulnerable. Use the command 'strings /path/to/u-boot | grep U-Boot' to check the version.

Impact Analysis

If exploited, this vulnerability could cause the U-Boot bootloader to crash during system startup. This may prevent the device from booting properly, leading to denial of service. Attackers could potentially execute arbitrary code if they gain control over the NFS server.

Mitigation Strategies

Upgrade U-Boot to version 2026.10-rc5 or later. Avoid using untrusted NFS servers during boot. Monitor network traffic for suspicious NFS responses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74221. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart