CVE-2026-71973: U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation
U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfsreaddirectorytable() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablkscount value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using U-Boot versions before 2026.10-rc4 are exposed when U-Boot processes a SquashFS image. The vulnerable code is the SquashFS directory-table handling path in sqfs_read_directory_table().
What does an attacker need to exploit it?
An attacker needs to provide a crafted SquashFS image whose superblock contains an attacker-controlled metablks_count value. That value can trigger an integer overflow during directory-table buffer allocation, leading to heap corruption and a bootloader crash.
What can be done if updating U-Boot is not immediately possible?
Avoid processing SquashFS images from untrusted sources. In particular, prevent attacker-supplied or modified SquashFS images from being used during boot or other U-Boot filesystem operations.
How can I determine whether I am affected?
Check the U-Boot version in use: versions before 2026.10-rc4 are affected. Also identify whether the deployment uses U-Boot's SquashFS support to read directory tables from supplied images.