U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. (CVE-2026-74222)
U-Boot versions prior to 2026.10-rc5 contain a use-after-free vulnerability in the httpc_recv_cb() function of the lwIP wget implementation. This flaw occurs when HTTP data storage fails, causing the callback to free the connection PCB but return an incorrect error code, leading to access of freed memory and potential bootloader crash.
AI Analysis
Technical Summary
The vulnerability in U-Boot before 2026.10-rc5 is a use-after-free issue located in the httpc_recv_cb() function within the lwIP wget implementation. Specifically, when HTTP data storage fails, the callback function frees the connection protocol control block (PCB) but returns ERR_BUF instead of ERR_ABRT. This incorrect error handling causes the TCP input path to access memory that has already been released, resulting in a crash of the bootloader.
Potential Impact
Successful exploitation of this vulnerability can cause the U-Boot bootloader to crash due to use-after-free memory access. The CVSS score of 8.2 indicates high severity with no confidentiality impact, limited integrity impact, and high availability impact. There is no indication of remote code execution or information disclosure from the provided data.
Mitigation Recommendations
A fix is available in U-Boot version 2026.10-rc5 and later. Users should upgrade to version 2026.10-rc5 or newer to remediate this vulnerability. No additional mitigation steps are indicated in the provided data.
U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. (CVE-2026-74222)
Description
U-Boot versions prior to 2026.10-rc5 contain a use-after-free vulnerability in the httpc_recv_cb() function of the lwIP wget implementation. This flaw occurs when HTTP data storage fails, causing the callback to free the connection PCB but return an incorrect error code, leading to access of freed memory and potential bootloader crash.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in U-Boot before 2026.10-rc5 is a use-after-free issue located in the httpc_recv_cb() function within the lwIP wget implementation. Specifically, when HTTP data storage fails, the callback function frees the connection protocol control block (PCB) but returns ERR_BUF instead of ERR_ABRT. This incorrect error handling causes the TCP input path to access memory that has already been released, resulting in a crash of the bootloader.
Potential Impact
Successful exploitation of this vulnerability can cause the U-Boot bootloader to crash due to use-after-free memory access. The CVSS score of 8.2 indicates high severity with no confidentiality impact, limited integrity impact, and high availability impact. There is no indication of remote code execution or information disclosure from the provided data.
Mitigation Recommendations
A fix is available in U-Boot version 2026.10-rc5 and later. Users should upgrade to version 2026.10-rc5 or newer to remediate this vulnerability. No additional mitigation steps are indicated in the provided data.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fm4f-g9jh-3qfq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74222"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abc5d44680226ef6899ba68
Added to database: 09/30/2026, 00:52:20 UTC
Last enriched: 09/30/2026, 01:06:23 UTC
Last updated: 09/30/2026, 01:27:31 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.