CVE-2026-71974
MEDIUM
4,3
Source: [email protected]
Attack Vector: physical
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,8
Source: [email protected]
Attack Vector: physical
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: high
Description
AI Translation Available
U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.
787
Out-of-bounds Write
DraftCommon Consequences
Security Scopes Affected:
Integrity
Availability
Other
Potential Impacts:
Modify Memory
Execute Unauthorized Code Or Commands
Dos: Crash, Exit, Or Restart
Unexpected State
Applicable Platforms
Languages:
Memory-Unsafe, C, C++, Assembly
Technologies:
ICS/OT
https://github.com/u-boot/u-boot
https://github.com/u-boot/u-boot/blob/v2026.07/boot/bootmeth_android.c#L356
https://github.com/u-boot/u-boot/commit/35432ef6fe2c79ab72709966e64815a45eb55c76
https://patch.msgid.link/20260729-b4-android-bootmeth-oob-v1-1-31c3450ae0be@byt…
https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-wr…