> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> USN-8884-1: U-Boot vulnerabilities

[SOURCE] Ubuntu Security Notices [DATE: 06/10/2026 16:09] [LANGUAGE: EN]
Timo Preißl discovered that U-Boot incorrectly handled certain malformed ZFS file system metadata. An attacker could possibly use this issue to trigger an integer overflow and out-of-bounds memory access, resulting in arbitrary code execution or a denial of service. (CVE-2025-70290) Timo Preißl discovered that U-Boot incorrectly calculated buffer sizes when processing certain ext4 file systems. An attacker could possibly use this issue to trigger an integer overflow and out-of-bounds memory access, resulting in arbitrary code execution or a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2025-70293) Mateusz Furdyna discovered that U-Boot incorrectly handled certain fragmented IP traffic when IP defragmentation was enabled. An attacker could possibly use this issue to corrupt memory by sending crafted IP fragments, resulting in arbitrary code execution. (CVE-2026-15390) Shahriyar Jalayeri and Mehrun P. Hunter discovered that U-Boot incorrectly handled certain fragmented IP traffic during network boot when IP defragmentation was enabled. An attacker could possibly use this issue to trigger an out-of-bounds write, resulting in a denial of service. (CVE-2026-71971)
[messages.read_original_source] →