Full Report
Out-of-bounds write vulnerability (CVE-2026-15390) has been found in DENX Software Engineering Das U-Boot software.
Analysis Summary
# Vulnerability: Out-of-Bounds Write in Das U-Boot IP Reassembly
## CVE Details
- **CVE ID:** CVE-2026-15390
- **CVSS Score:** Not explicitly rated in the report (Typically High/Critical for RCE in bootloaders)
- **CWE:** CWE-787 (Out-of-bounds Write)
## Affected Systems
- **Products:** DENX Software Engineering Das U-Boot
- **Versions:** From version 2009.08 through 2026.07
- **Configurations:** Systems compiled with the configuration parameter `CONFIG_IP_DEFRAG=y` enabled.
## Vulnerability Description
The flaw exists within the IP packet reassembly logic of Das U-Boot. Specifically, the software fails to properly clear the IP reassembly state after a complete datagram has been successfully delivered. This logic error allows an attacker to manipulate the reassembly buffer. By sending duplicated "last-fragment" IP packets, an attacker can trigger an out-of-bounds write to memory.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild; coordinated disclosure.
- **Complexity:** Medium (Requires crafted fragmented IP traffic).
- **Attack Vector:** Adjacent/Network (Requires the ability to deliver IP traffic to the device during the boot stage where U-Boot networking is active).
## Impact
- **Confidentiality:** High (Potential for full system compromise).
- **Integrity:** High (Arbitrary code execution).
- **Availability:** High (Device crash or permanent bricking if the boot process is subverted).
## Remediation
### Patches
- The vulnerability has been fixed in **Das U-Boot version 2026.07**.
- Specific fix: Commit `b1aec609bb5e0d08c25c888c91935287ab4ee5fa`.
### Workarounds
- Disable `CONFIG_IP_DEFRAG` in the U-Boot configuration if IP fragmentation support is not strictly required for the boot process.
- Restrict network access to the device during the bootloader phase to trusted segments only.
## Detection
- **Indicators of Compromise:** Unexpected crashes or reboots during the network boot process; malformed IP fragments (specifically overlapping or duplicate last fragments) detected by network intrusion detection systems (NIDS).
- **Detection Methods:** Static analysis of U-Boot configuration files (`.config`) to check for `CONFIG_IP_DEFRAG=y`.
## References
- **Vendor Advisory:** hxxps[://]cert[.]pl/en/posts/2026/09/CVE-2026-15390/
- **CVE Record:** hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-15390
- **CWE-787 Details:** hxxps[://]cwe[.]mitre[.]org/data/definitions/787[.]html