CyberRota Analysis
AI-GeneratedA buffer overflow vulnerability in the nfs_readlink_reply() function of U-Boot can be exploited by a malicious NFS server to send crafted READLINK replies, potentially leading to memory corruption and bootloader crashes. Organizations using U-Boot, particularly in embedded systems and networked environments, should prioritize patching this vulnerability to mitigate risks of system instability and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.