CVE-2026-15390
Out-of-bounds write in Das U-Boot
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
| CWE | CWE-787 CWE-459 |
| Vendor | denx software engineering |
| Product | das u-boot |
| Published | Sep 29, 2026 |
| Last Updated | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for denx software engineering das u-boot
Be the first to know when new unknown vulnerabilities affecting denx software engineering das u-boot are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
DENX Software Engineering / Das U-Boot
2009.08 ≤ 2026.07
References
Credits
Mateusz Furdyna, Nokia