SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2025-70290

CRITICAL · CVSS 9.8 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the ZFS filesystem support of Denx U-Boot can be exploited through malformed on-disk metadata, leading to incorrect memory allocation and potential out-of-bounds memory access. This may result in system crashes or arbitrary code execution during the boot process. Organizations utilizing affected versions of Denx U-Boot should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-70290
Severity
CRITICAL
CVSS
9.8
EPSS
0.46%

Original NVD Description

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.