CVE-2026-71974

medium

Description

U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.

References

https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-via-android-bootmeth-partition-read

https://patch.msgid.link/[email protected]

https://github.com/u-boot/u-boot/commit/35432ef6fe2c79ab72709966e64815a45eb55c76

https://github.com/u-boot/u-boot/blob/v2026.07/boot/bootmeth_android.c#L356

https://github.com/u-boot/u-boot

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89432

Details

Source: Mitre, NVD

Published: 2026-09-29

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 4.7

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 4.8

Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Severity: Medium

CVSS v4

Base Score: 4.3

Vector: CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00177