CVE-2026-74221: U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK

Published Sep 29, 2026
·
Updated

U-Boot before 2026.10-rc5 contains a buffer overflow in nfsreadlinkreply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.

Affected Software

1 affected component
U-Boot U-boot<2026.10-rc5

Event History

Sep 29, 2026
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

U-Boot versions before 2026.10-rc5 are affected when they process NFS READLINK responses. Exposure requires the bootloader to communicate with an NFS server that can provide those responses.

2

What does an attacker need to exploit the vulnerability?

An attacker needs to operate or control a reachable malicious NFS server, or otherwise be able to cause U-Boot to receive crafted NFS READLINK replies. No authentication or user interaction is indicated by the provided vector.

3

What is the practical impact of successful exploitation?

Crafted negative or oversized symlink length values can corrupt U-Boot memory and crash the bootloader. The supplied impact metrics indicate high availability impact and low integrity impact, with no confidentiality impact.

4

What can be done if upgrading is not immediately possible?

Do not use untrusted or attacker-controlled NFS servers for U-Boot network boot operations, and restrict network access so U-Boot can only reach trusted NFS infrastructure. The provided data does not identify another workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203