U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. (CVE-2026-74221)
U-Boot versions prior to 2026.10-rc5 contain a buffer overflow vulnerability in the nfs_readlink_reply() function within net/nfs-common.c. This occurs when processing NFS server responses, where a malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values. This can lead to memory corruption and cause the bootloader to crash.
AI Analysis
Technical Summary
The vulnerability CVE-2026-74221 affects U-Boot before version 2026.10-rc5. It is a buffer overflow in the nfs_readlink_reply() function in net/nfs-common.c triggered by malicious NFS server responses containing crafted READLINK replies with negative or oversized symlink length values. This flaw can corrupt memory and crash the bootloader during the processing of these responses.
Potential Impact
An attacker controlling an NFS server can exploit this vulnerability to cause memory corruption and crash the U-Boot bootloader on affected systems. This results in denial of service (bootloader crash) but does not have confirmed impact on confidentiality or integrity according to the CVSS vector.
Mitigation Recommendations
A fix is available in U-Boot version 2026.10-rc5. Users should upgrade to this version or later to remediate the vulnerability. No additional mitigation guidance is provided or required beyond applying the official fix.
U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. (CVE-2026-74221)
Description
U-Boot versions prior to 2026.10-rc5 contain a buffer overflow vulnerability in the nfs_readlink_reply() function within net/nfs-common.c. This occurs when processing NFS server responses, where a malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values. This can lead to memory corruption and cause the bootloader to crash.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-74221 affects U-Boot before version 2026.10-rc5. It is a buffer overflow in the nfs_readlink_reply() function in net/nfs-common.c triggered by malicious NFS server responses containing crafted READLINK replies with negative or oversized symlink length values. This flaw can corrupt memory and crash the bootloader during the processing of these responses.
Potential Impact
An attacker controlling an NFS server can exploit this vulnerability to cause memory corruption and crash the U-Boot bootloader on affected systems. This results in denial of service (bootloader crash) but does not have confirmed impact on confidentiality or integrity according to the CVSS vector.
Mitigation Recommendations
A fix is available in U-Boot version 2026.10-rc5. Users should upgrade to this version or later to remediate the vulnerability. No additional mitigation guidance is provided or required beyond applying the official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-r9ch-9wx4-f978
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74221"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abc5d44680226ef6899ba63
Added to database: 09/30/2026, 00:52:20 UTC
Last enriched: 09/30/2026, 01:06:30 UTC
Last updated: 09/30/2026, 03:09:00 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.