Bug 2543686 (CVE-2026-71974) - CVE-2026-71974 uboot-tools: U-Boot: Out-of-bounds write via Android boot partition read
Summary: CVE-2026-71974 uboot-tools: U-Boot: Out-of-bounds write via Android boot part...
Keywords:
Status: NEW
Alias: CVE-2026-71974
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2543795 2543796
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-29 21:43 UTC by OSIDB Bzimport
Modified: 2026-09-30 04:12 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-29 21:43:04 UTC
U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.


Note You need to log in before you can comment on or make changes to this bug.