CVE-2026-71972: U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder
U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the videodisplayrle8bitmap function in drivers/video/videobmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.
Affected Software
Event History
Frequently Asked Questions
What access and attacker capabilities are required for exploitation?
The reported vector is adjacent-network access, and exploitation does not require privileges or user interaction. The attacker must be able to supply a crafted RLE8-compressed BMP image for U-Boot to process.
What is the expected operational impact?
A successful exploit can corrupt memory adjacent to the framebuffer and crash the bootloader. The supplied scoring indicates no confidentiality impact, but low integrity impact and high availability impact.
What versions should be included in an exposure review?
Include U-Boot versions through 2026.10-rc5 in the review. The provided data does not identify a fixed release version.