> USN-8884-1: U-Boot vulnerabilities
[DATE: 06/10/2026 16:09]
[LANGUAGE: EN]
Timo Preißl discovered that U-Boot incorrectly handled certain malformed
ZFS file system metadata. An attacker could possibly use this issue to
trigger an integer overflow and out-of-bounds memory access, resulting in
arbitrary code execution or a denial of service. (CVE-2025-70290)
Timo Preißl discovered that U-Boot incorrectly calculated buffer sizes when
processing certain ext4 file systems. An attacker could possibly use this
issue to trigger an integer overflow and out-of-bounds memory access,
resulting in arbitrary code execution or a denial of service. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2025-70293)
Mateusz Furdyna discovered that U-Boot incorrectly handled certain
fragmented IP traffic when IP defragmentation was enabled. An attacker
could possibly use this issue to corrupt memory by sending crafted IP
fragments, resulting in arbitrary code execution. (CVE-2026-15390)
Shahriyar Jalayeri and Mehrun P. Hunter discovered that U-Boot incorrectly
handled certain fragmented IP traffic during network boot when IP
defragmentation was enabled. An attacker could possibly use this issue to
trigger an out-of-bounds write, resulting in a denial of service.
(CVE-2026-71971)