Skip to main content

U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against… (CVE-2026-71974)

0
Medium
Published: 09/30/2026 (09/30/2026, 00:32:29 UTC)
Source: GCVE Database

Description

U-Boot versions prior to 2026.10-rc3 have an out-of-bounds write vulnerability in the read_slotted_partition() function. This flaw occurs because the image size is not properly validated against partition bounds, allowing an attacker with physical access to supply crafted boot media with oversized headers. This can lead to memory corruption in the bootloader on devices that do not have Android Verified Boot protection.

CVSS v3.1

Score 4.8medium

Attack Vector
Physical
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected software

GitHub Actionsmore threats →ai
u-boot/u-boot
pkg:github/u-boot/u-boot
Affected versions
<2026.10-rc3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 01:07:27 UTC

Technical Analysis

The vulnerability (CVE-2026-71974) in U-Boot before version 2026.10-rc3 is an out-of-bounds write in the read_slotted_partition() function. The function fails to validate the image size against the partition bounds, which can cause writes beyond the intended buffer. Exploitation requires physical access to the device to provide malicious boot media with oversized headers. Devices lacking Android Verified Boot protection are susceptible to memory corruption in the bootloader due to this flaw.

Potential Impact

An attacker with physical access can cause an out-of-bounds write in the bootloader memory, potentially leading to denial of service or bootloader corruption. The vulnerability does not impact confidentiality but can affect integrity and availability of the boot process. Devices with Android Verified Boot protection are not vulnerable to this attack vector.

Mitigation Recommendations

Upgrade U-Boot to version 2026.10-rc3 or later where this vulnerability is fixed. Devices with Android Verified Boot protection are not affected by this issue. If upgrading is not immediately possible, ensure physical security to prevent attacker access to boot media.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-c7vr-vjm2-3grc
Osv Schema Version
1.4.0
Aliases
["CVE-2026-71974"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6abc5d46680226ef6899ba71

Added to database: 09/30/2026, 00:52:22 UTC

Last enriched: 09/30/2026, 01:07:27 UTC

Last updated: 09/30/2026, 03:09:21 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses