🔐 CVE Alert

CVE-2026-15390

UNKNOWN 0.0

Out-of-bounds write in Das U-Boot

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.

CWE CWE-787 CWE-459
Vendor denx software engineering
Product das u-boot
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for denx software engineering das u-boot

Be the first to know when new unknown vulnerabilities affecting denx software engineering das u-boot are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

DENX Software Engineering / Das U-Boot
2009.08 ≤ 2026.07

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/09/CVE-2026-15390 source.denx.de: https://source.denx.de/u-boot/u-boot/-/commit/b1aec609bb5e0d08c25c888c91935287ab4ee5fa

Credits

Mateusz Furdyna, Nokia