U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against… (CVE-2026-71974)
U-Boot versions prior to 2026.10-rc3 have an out-of-bounds write vulnerability in the read_slotted_partition() function. This flaw occurs because the image size is not properly validated against partition bounds, allowing an attacker with physical access to supply crafted boot media with oversized headers. This can lead to memory corruption in the bootloader on devices that do not have Android Verified Boot protection.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-71974) in U-Boot before version 2026.10-rc3 is an out-of-bounds write in the read_slotted_partition() function. The function fails to validate the image size against the partition bounds, which can cause writes beyond the intended buffer. Exploitation requires physical access to the device to provide malicious boot media with oversized headers. Devices lacking Android Verified Boot protection are susceptible to memory corruption in the bootloader due to this flaw.
Potential Impact
An attacker with physical access can cause an out-of-bounds write in the bootloader memory, potentially leading to denial of service or bootloader corruption. The vulnerability does not impact confidentiality but can affect integrity and availability of the boot process. Devices with Android Verified Boot protection are not vulnerable to this attack vector.
Mitigation Recommendations
Upgrade U-Boot to version 2026.10-rc3 or later where this vulnerability is fixed. Devices with Android Verified Boot protection are not affected by this issue. If upgrading is not immediately possible, ensure physical security to prevent attacker access to boot media.
U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against… (CVE-2026-71974)
Description
U-Boot versions prior to 2026.10-rc3 have an out-of-bounds write vulnerability in the read_slotted_partition() function. This flaw occurs because the image size is not properly validated against partition bounds, allowing an attacker with physical access to supply crafted boot media with oversized headers. This can lead to memory corruption in the bootloader on devices that do not have Android Verified Boot protection.
CVSS v3.1
Score 4.8medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-71974) in U-Boot before version 2026.10-rc3 is an out-of-bounds write in the read_slotted_partition() function. The function fails to validate the image size against the partition bounds, which can cause writes beyond the intended buffer. Exploitation requires physical access to the device to provide malicious boot media with oversized headers. Devices lacking Android Verified Boot protection are susceptible to memory corruption in the bootloader due to this flaw.
Potential Impact
An attacker with physical access can cause an out-of-bounds write in the bootloader memory, potentially leading to denial of service or bootloader corruption. The vulnerability does not impact confidentiality but can affect integrity and availability of the boot process. Devices with Android Verified Boot protection are not vulnerable to this attack vector.
Mitigation Recommendations
Upgrade U-Boot to version 2026.10-rc3 or later where this vulnerability is fixed. Devices with Android Verified Boot protection are not affected by this issue. If upgrading is not immediately possible, ensure physical security to prevent attacker access to boot media.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c7vr-vjm2-3grc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71974"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6abc5d46680226ef6899ba71
Added to database: 09/30/2026, 00:52:22 UTC
Last enriched: 09/30/2026, 01:07:27 UTC
Last updated: 09/30/2026, 03:09:21 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.