CVE-2026-15390: Out-of-bounds write in Das U-Boot
Das U-Boot with CONFIGIPDEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Das U-Bootto a version that resolves this vulnerability.Fixed in 2026.07Patch b1aec609bb5e0d08c25c888c91935287ab4ee5fa
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments of Das U-Boot built with CONFIG_IP_DEFRAG=y are affected. Exposure also requires that the device can receive attacker-supplied fragmented IP traffic.
What must an attacker be able to do to exploit it?
An attacker needs to deliver fragmented IP packets to the affected U-Boot environment, including duplicated last fragments. Successful exploitation can result in arbitrary code execution.
What version contains the fix?
The issue was fixed in version 2026.07 in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa.