Description
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
Published: 2026-08-26
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution during boot
Action: Patch ASAP
AI Analysis

Impact

An integer overflow in the ZFS filesystem support of Denx U‑Boot before version 2026.04 can be triggered by malformed on‑disk metadata. The overflow leads to incorrect memory allocation and out‑of‑bounds access, which may cause a crash or, worse, arbitrary code execution while the system boots. Since this occurs during startup, success could compromise the entire firmware, allowing an attacker to gain full control without needing higher privileges on the running system.

Affected Systems

Denx U‑Boot images built before 2026.04 with ZFS filesystem support enabled, which includes most embedded devices that depend on this bootloader. Specific vendors or products are not listed, so any firmware image that incorporates the vulnerable U‑Boot version and has ZFS support is potentially affected.

Risk and Exploitability

The vulnerability can be exploited during the boot sequence by supplying crafted on‑disk metadata. The CVSS score of 9.8 indicates a critical impact. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be the boot media, so an attac​tor with physical or remote access to the device’s media could trigger the flaw and achieve arbitrary code execution.

Generated by OpenCVE AI on August 28, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy a U‑Boot image from Denx released after the 2026.04 version that contains the fix for the ZFS integer overflow
  • If an immediate upgrade is not possible, rebuild U‑Boot excluding ZFS filesystem support or disable it in the configuration to eliminate the vulnerable code path
  • Monitor boot logs for abnormal termination or out‑of‑bounds access traces and report any incidents to Denx for further guidance

Generated by OpenCVE AI on August 28, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Denx U‑Boot ZFS Filesystem Integer Overflow leading to Arbitrary Code Execution during Boot

Fri, 28 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Denx U‑Boot ZFS Support Enables Boot‑time Arbitrary Code Execution
Weaknesses CWE-119

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Denx U‑Boot ZFS Support Enables Boot‑time Arbitrary Code Execution
Weaknesses CWE-119
CWE-190

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared U-boot
U-boot u-boot
Vendors & Products U-boot
U-boot u-boot

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T19:10:50.219Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70290

cve-icon Vulnrichment

Updated: 2026-08-27T19:10:40.937Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T20:16:59.550

Modified: 2026-09-09T16:04:24.933

Link: CVE-2025-70290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:30:08Z

Weaknesses