Impact
An integer overflow in the ZFS filesystem support of Denx U‑Boot before version 2026.04 can be triggered by malformed on‑disk metadata. The overflow leads to incorrect memory allocation and out‑of‑bounds access, which may cause a crash or, worse, arbitrary code execution while the system boots. Since this occurs during startup, success could compromise the entire firmware, allowing an attacker to gain full control without needing higher privileges on the running system.
Affected Systems
All embedded devices that run Denx U‑Boot before the 2026.04 release and have ZFS filesystem support enabled. Specific vendors or products are not enumerated, so any firmware image built with the vulnerable U‑Boot version is potentially affected.
Risk and Exploitability
The vulnerability can be exploited during the boot sequence by supplying crafted on‑disk metadata. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but the absence of a fix and the high impact of arbitrary code execution imply a serious risk. The attack vector is inferred to be the boot media, meaning that an attacker with physical or remote access to the media can trigger the flaw.
OpenCVE Enrichment