CVE-2026-74225
Publication date 29 September 2026
Last updated 30 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| u-boot | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| u-boot-nezha | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
Severity score breakdown
CVSS version:
Base score
7.1 · High
Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Base score
7.1 · High
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-74225
- https://github.com/u-boot/u-boot
- https://github.com/u-boot/u-boot/blob/v2026.07/net/dhcpv6.c#L304
- https://github.com/u-boot/u-boot/commit/20209a62bc8565fc1e040882bc03c71ff0d73076
- https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-out-of-bounds-write-via-dhcpv6