Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader. | |
| Title | U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly | |
| First Time appeared |
Denx
Denx u-boot |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Denx
Denx u-boot |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T21:29:20.055Z
Reserved: 2026-08-08T16:43:04.178Z
Link: CVE-2026-71971
No data.
Status : Received
Published: 2026-09-29T22:18:21.723
Modified: 2026-09-29T22:18:21.723
Link: CVE-2026-71971
No data.
OpenCVE Enrichment
No data.
