CVE-2026-74221: U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK
U-Boot before 2026.10-rc5 contains a buffer overflow in nfsreadlinkreply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
U-Boot versions before 2026.10-rc5 are affected when they process NFS READLINK responses. Exposure requires the bootloader to communicate with an NFS server that can provide those responses.
What does an attacker need to exploit the vulnerability?
An attacker needs to operate or control a reachable malicious NFS server, or otherwise be able to cause U-Boot to receive crafted NFS READLINK replies. No authentication or user interaction is indicated by the provided vector.
What is the practical impact of successful exploitation?
Crafted negative or oversized symlink length values can corrupt U-Boot memory and crash the bootloader. The supplied impact metrics indicate high availability impact and low integrity impact, with no confidentiality impact.
What can be done if upgrading is not immediately possible?
Do not use untrusted or attacker-controlled NFS servers for U-Boot network boot operations, and restrict network access so U-Boot can only reach trusted NFS infrastructure. The provided data does not identify another workaround.