← ALL ADVISORIES

HIGH BYTERAY-2026-0214Disclosed

U-Boot — Integer Overflow in SquashFS Directory-Table Allocation

A size computation for the SquashFS directory table overflows on an attacker-controlled superblock field, producing an undersized allocation and subsequent out-of-bounds writes when U-Boot parses a crafted SquashFS image during boot.

Advisory
BYTERAY-2026-0214
CVE
CVE-2026-71973
CWE
CWE-190
CVSS
5.2 (CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 5.2 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Vendor
U-Boot
Product
U-Boot
Reported
2026-07-28
Disclosure
2026-09-29
Affected
U-Boot before 2026.10-rc4
Fixed in
2026.10-rc4 (commit 561ae28cb56a082cfa90c1c421c4955bc215470b)

Executive Summary

U-Boot can parse a SquashFS image from storage during boot, for example to load a kernel, before that image is verified. The allocation size for the SquashFS directory table is computed from an attacker-controlled header field and can overflow, so the buffer is under-allocated and later writes run past its end. A crafted SquashFS image therefore corrupts heap memory inside the bootloader.

Affected Products and Versions

  • Product: U-Boot, SquashFS directory table handling in fs/squashfs/sqfs.c (sqfs_read_directory_table()).
  • Affected: U-Boot before 2026.10-rc4.
  • Fixed: 2026.10-rc4 and later.

Technical Details

sqfs_read_directory_table() computes the size of the directory-table buffer from the superblock's attacker-controlled metablks_count value. The computation can overflow, so the allocation is smaller than the data that is subsequently written into it, producing heap buffer under-allocation and out-of-bounds writes when a crafted SquashFS image is parsed.

Reachability and Preconditions

  • U-Boot parses a SquashFS image during boot (for example to load a kernel) from storage the attacker can supply, before that artifact is verified.

Impact

Heap buffer under-allocation and out-of-bounds writes that corrupt heap memory and crash the bootloader. Because the parse runs inside U-Boot, the verified-boot enforcer, before the artifact is verified, the corruption can lead to a secure-boot bypass.

Remediation and Mitigation

Update U-Boot to 2026.10-rc4 or later, which contains commit 561ae28cb56a082cfa90c1c421c4955bc215470b. Where possible, avoid parsing SquashFS images from untrusted storage before verification until the fix is deployed.

Timeline

  • 2026-07-28 — Vulnerability public and fix available upstream.
  • 2026.10-rc4 — Fix released (commit 561ae28cb56a082cfa90c1c421c4955bc215470b).
  • 2026-09-29 — CVE-2026-71973 record published by VulnCheck.

Credits

Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.

References