CyberRota Analysis
AI-GeneratedU-Boot versions prior to 2026.10-rc5 are vulnerable to an out-of-bounds memory access due to improper validation of SERVERID and CLIENTID option lengths in DHCPv6 packets. This flaw allows attackers on the same local network to send malicious DHCPv6 ADVERTISE or REPLY packets, potentially leading to memory corruption and bootloader crashes. Organizations utilizing U-Boot in their networked devices should prioritize patching this vulnerability to mitigate the risk of local network attacks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.