UBUNTU-CVE-2026-29007
U-Boot versions through 2026.04-rc3 contain an out-of-bounds read vulnerability in the tcp_rx_state_machine() function when CONFIG_PROT_TCP is enabled. This flaw allows remote attackers to craft malicious TCP packets with mismatched IP total length and TCP data offset fields, causing the system to read beyond TCP segment boundaries. The vulnerability can corrupt TCP connection state variables such as rmt_win_scale and rmt_timestamp, potentially disrupting TCP window calculations and connection stability.
AI Analysis
Technical Summary
The vulnerability exists in U-Boot's tcp_rx_state_machine() function (net/tcp.c) when CONFIG_PROT_TCP is enabled. An attacker can send a TCP packet with an IP total length smaller than the TCP data offset claims, causing tcp_parse_options() to read beyond the actual TCP segment boundary by up to 40 bytes. This out-of-bounds read can corrupt connection state variables such as rmt_win_scale and rmt_timestamp, which may disrupt TCP window calculations and affect TCP connection behavior. The issue affects multiple Ubuntu-packaged versions of U-Boot up to 2026.04-rc3.
Potential Impact
Remote attackers can exploit this vulnerability by sending specially crafted TCP packets that cause out-of-bounds reads in the TCP processing code. This can lead to corruption of TCP connection state variables, potentially disrupting TCP window calculations and causing instability or denial of service in affected systems using U-Boot with TCP support enabled.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor Ubuntu and U-Boot vendor advisories for updates addressing this vulnerability. Until a patch is available, disabling CONFIG_PROT_TCP if feasible may mitigate exposure.
UBUNTU-CVE-2026-29007
Description
U-Boot versions through 2026.04-rc3 contain an out-of-bounds read vulnerability in the tcp_rx_state_machine() function when CONFIG_PROT_TCP is enabled. This flaw allows remote attackers to craft malicious TCP packets with mismatched IP total length and TCP data offset fields, causing the system to read beyond TCP segment boundaries. The vulnerability can corrupt TCP connection state variables such as rmt_win_scale and rmt_timestamp, potentially disrupting TCP window calculations and connection stability.
CVSS v4.0
Affected software
pkg:deb/ubuntu/[email protected]+dfsg1-2ubuntu5?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]+dfsg-1ubuntu0~18.04.3?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]+dfsg-3ubuntu0~20.04.6?arch=source&distro=focalpkg:deb/ubuntu/[email protected]+dfsg-2ubuntu2.7?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+git20220405.7446a472-0ubuntu0.4?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~rc1-190-g2e89b706f5-0ubuntu2?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in U-Boot's tcp_rx_state_machine() function (net/tcp.c) when CONFIG_PROT_TCP is enabled. An attacker can send a TCP packet with an IP total length smaller than the TCP data offset claims, causing tcp_parse_options() to read beyond the actual TCP segment boundary by up to 40 bytes. This out-of-bounds read can corrupt connection state variables such as rmt_win_scale and rmt_timestamp, which may disrupt TCP window calculations and affect TCP connection behavior. The issue affects multiple Ubuntu-packaged versions of U-Boot up to 2026.04-rc3.
Potential Impact
Remote attackers can exploit this vulnerability by sending specially crafted TCP packets that cause out-of-bounds reads in the TCP processing code. This can lead to corruption of TCP connection state variables, potentially disrupting TCP window calculations and causing instability or denial of service in affected systems using U-Boot with TCP support enabled.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor Ubuntu and U-Boot vendor advisories for updates addressing this vulnerability. Until a patch is available, disabling CONFIG_PROT_TCP if feasible may mitigate exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-29007
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a58b4d868715ace43dabc17
Added to database: 07/16/2026, 10:39:20 UTC
Last enriched: 07/16/2026, 13:35:18 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.