https://seclists.org/oss-sec/2026/q3/607: Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293)
Published Aug 28, 2026
·Updated
Affected Software
1 affected component
DENX U-Boot<=v2026.01-rc4
Frequently Asked Questions
1
Which U-Boot releases need to be updated?
DENX U-Boot releases through v2026.01-rc4 are affected. The issues are fixed in v2026.04-rc1, commit adccdb2.
2
What input is known to trigger one of these flaws?
For CVE-2025-70290, a crafted ZFS filesystem image containing malformed on-disk metadata can trigger the vulnerable allocation-size calculation in zfs_nvlist_lookup_nvlist.