Impact
An integer overflow in the ZFS filesystem support of Denx U‑Boot before version 2026.04 can be triggered by malformed on‑disk metadata. The overflow leads to incorrect memory allocation and out‑of‑bounds access, which may cause a crash or, worse, arbitrary code execution while the system boots. Since this occurs during startup, success could compromise the entire firmware, allowing an attacker to gain full control without needing higher privileges on the running system.
Affected Systems
Denx U‑Boot images built before 2026.04 with ZFS filesystem support enabled, which includes most embedded devices that depend on this bootloader. Specific vendors or products are not listed, so any firmware image that incorporates the vulnerable U‑Boot version and has ZFS support is potentially affected.
Risk and Exploitability
The vulnerability can be exploited during the boot sequence by supplying crafted on‑disk metadata. The CVSS score of 9.8 indicates a critical impact. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be the boot media, so an attactor with physical or remote access to the device’s media could trigger the flaw and achieve arbitrary code execution.
OpenCVE Enrichment