CVE-2026-15390: CWE-787 Out-of-bounds write in DENX Software Engineering Das U-Boot
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
AI Analysis
Technical Summary
CVE-2026-15390 is an out-of-bounds write vulnerability (CWE-787) in DENX Software Engineering's Das U-Boot bootloader when configured with CONFIG_IP_DEFRAG=y. The vulnerability arises because the IP reassembly state is not cleared after a complete datagram is delivered, enabling an attacker capable of sending fragmented IP packets to execute arbitrary code by sending duplicated last-fragment IP packets. The vulnerability was addressed and fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa included in version 2026.07.
Potential Impact
An attacker who can deliver fragmented IP traffic to a vulnerable Das U-Boot instance with CONFIG_IP_DEFRAG=y can execute arbitrary code remotely. This can lead to full compromise of the affected device's bootloader environment. The CVSS 4.0 score is 9.0 (critical), reflecting high impact on confidentiality, integrity, and availability with low attack complexity and no required privileges or user interaction.
Mitigation Recommendations
This vulnerability has been fixed in Das U-Boot version 2026.07. Users should upgrade to version 2026.07 or later to remediate this issue. No other mitigation is indicated or required as the fix is official and available.
CVE-2026-15390: CWE-787 Out-of-bounds write in DENX Software Engineering Das U-Boot
Description
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
CVSS v4.0
Score 9.0critical
Affected software
DENX Software Engineering
Das U-Boot
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15390 is an out-of-bounds write vulnerability (CWE-787) in DENX Software Engineering's Das U-Boot bootloader when configured with CONFIG_IP_DEFRAG=y. The vulnerability arises because the IP reassembly state is not cleared after a complete datagram is delivered, enabling an attacker capable of sending fragmented IP packets to execute arbitrary code by sending duplicated last-fragment IP packets. The vulnerability was addressed and fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa included in version 2026.07.
Potential Impact
An attacker who can deliver fragmented IP traffic to a vulnerable Das U-Boot instance with CONFIG_IP_DEFRAG=y can execute arbitrary code remotely. This can lead to full compromise of the affected device's bootloader environment. The CVSS 4.0 score is 9.0 (critical), reflecting high impact on confidentiality, integrity, and availability with low attack complexity and no required privileges or user interaction.
Mitigation Recommendations
This vulnerability has been fixed in Das U-Boot version 2026.07. Users should upgrade to version 2026.07 or later to remediate this issue. No other mitigation is indicated or required as the fix is official and available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-07-10T11:51:31.347Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abb9075f7a7c54106366dd6
Added to database: 09/29/2026, 10:18:29 UTC
Last enriched: 09/29/2026, 10:32:52 UTC
Last updated: 09/29/2026, 13:41:31 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.