Skip to main content

U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths… (CVE-2026-74225)

0
High
Published: 09/30/2026 (09/30/2026, 00:32:29 UTC)
Source: GCVE Database

Description

U-Boot versions prior to 2026.10-rc5 contain an out-of-bounds memory access vulnerability in the dhcp6_parse_options() function. This flaw arises from improper validation of SERVERID and CLIENTID option lengths in DHCPv6 packets. An attacker on the local network can exploit this by sending crafted DHCPv6 ADVERTISE or REPLY packets during netboot, potentially causing memory corruption and crashing the bootloader.

CVSS v3.1

Score 7.1high

Attack Vector
Adjacent Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected software

GitHub Actionsmore threats →ai
u-boot/u-boot
pkg:github/u-boot/u-boot
Affected versions
<2026.10-rc5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 01:06:19 UTC

Technical Analysis

The vulnerability in U-Boot before version 2026.10-rc5 is due to a failure to validate the lengths of SERVERID and CLIENTID options in DHCPv6 packets within the dhcp6_parse_options() function. This leads to out-of-bounds memory access, which can be triggered by an attacker on the local network sending malicious DHCPv6 ADVERTISE or REPLY packets during the netboot process. The result is memory corruption that can crash the bootloader, impacting system availability.

Potential Impact

Exploitation of this vulnerability can cause the U-Boot bootloader to crash due to memory corruption. This affects system availability during the boot process but does not impact confidentiality or integrity directly according to the CVSS vector. The attack requires local network access and no privileges or user interaction are needed.

Mitigation Recommendations

A fix is available in U-Boot version 2026.10-rc5 and later. Users should upgrade to this version or a later release to remediate the vulnerability. No additional mitigation steps are indicated in the provided data.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-c478-wgg8-3gvq
Osv Schema Version
1.4.0
Aliases
["CVE-2026-74225"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6abc5d46680226ef6899ba72

Added to database: 09/30/2026, 00:52:22 UTC

Last enriched: 09/30/2026, 01:06:19 UTC

Last updated: 09/30/2026, 01:27:28 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses