CVE-2026-71972: U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder

Published Sep 29, 2026
·
Updated

U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the videodisplayrle8bitmap function in drivers/video/videobmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.

Affected Software

1 affected component
U-Boot U-boot<=2026.10-rc5

Event History

Sep 29, 2026
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:18 PM
DescriptionSeverityWeakness
Oct 4, 58715
Event
via NVD·07:22 PM

Frequently Asked Questions

1

What access and attacker capabilities are required for exploitation?

The reported vector is adjacent-network access, and exploitation does not require privileges or user interaction. The attacker must be able to supply a crafted RLE8-compressed BMP image for U-Boot to process.

2

What is the expected operational impact?

A successful exploit can corrupt memory adjacent to the framebuffer and crash the bootloader. The supplied scoring indicates no confidentiality impact, but low integrity impact and high availability impact.

3

What versions should be included in an exposure review?

Include U-Boot versions through 2026.10-rc5 in the review. The provided data does not identify a fixed release version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203