CVE-2026-71971
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in
CVSS
8.2
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-787
Not enough EPSS history yet.
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
- github.comhttps://github.com/u-boot/u-boot
- github.comhttps://github.com/u-boot/u-boot/blob/v2026.07/net/net.c#L975
- github.comhttps://github.com/u-boot/u-boot/commit/04ca915d5bf39dda5d1bce62d04d2b59d293c5b9
- www.vulncheck.comhttps://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-in-ip-fragment-reassembly
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-81433——
——0A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.5hCVE-2026-742257.1 HIG—
——0U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.7hCVE-2026-719744.8 MED—
——0U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.7hCVE-2026-719725.9 MED—
——0U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.7hCVE-2026-1023018.3 HIG—
——0Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)8hCVE-2026-953579.6 CRI—
——0Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)10h