OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-74221

HIGH · CVSS 8.2 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A buffer overflow vulnerability in the nfs_readlink_reply() function of U-Boot can be exploited by a malicious NFS server to send crafted READLINK replies, potentially leading to memory corruption and bootloader crashes. Organizations using U-Boot, particularly in embedded systems and networked environments, should prioritize patching this vulnerability to mitigate risks of system instability and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74221
Severity
HIGH
CVSS
8.2
EPSS
0.34%

Original NVD Description

U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.