U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
Published Jul 8, 2026
8.8
HIGHCVSS 4.0
EPSS 0.74%
Description
U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
Affected products
-
Affected
- ≥ 0, < 2026.07-rc2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42333 Advisory
- https://git.u-boot-project.org/u-boot/u-boot/-/commit/d6694018eaddefac6aae974f9cec72fd6e58f1bc patch
- https://git.u-boot-project.org/u-boot/u-boot/-/releases/v2026.07-rc2 release-notes
- https://lists.denx.de/pipermail/u-boot/2026-May/617853.html issue-trackingMailing ListThird Party Advisory
- https://u-boot.org/ Product
- https://www.vulncheck.com/advisories/u-boot-rc3-buffer-overflow-in-nfs-readlink-reply-via-nfs-readlink third-party-advisoryExploitThird Party Advisory
- https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/ technical-descriptionexploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42333 | Advisory | |
| https://git.u-boot-project.org/u-boot/u-boot/-/commit/d6694018eaddefac6aae974f9cec72fd6e58f1bc | patch | |
| https://git.u-boot-project.org/u-boot/u-boot/-/releases/v2026.07-rc2 | release-notes | |
| https://lists.denx.de/pipermail/u-boot/2026-May/617853.html | issue-trackingMailing ListThird Party Advisory | |
| https://u-boot.org/ | Product | |
| https://www.vulncheck.com/advisories/u-boot-rc3-buffer-overflow-in-nfs-readlink-reply-via-nfs-readlink | third-party-advisoryExploitThird Party Advisory | |
| https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/ | technical-descriptionexploitThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data