U-Boot — Integer Overflow in SquashFS Directory-Table Allocation
A size computation for the SquashFS directory table overflows on an attacker-controlled superblock field, producing an undersized allocation and subsequent out-of-bounds writes when U-Boot parses a crafted SquashFS image during boot.
- Advisory
- BYTERAY-2026-0214
- CVE
- CVE-2026-71973
- CWE
- CWE-190
- CVSS
- 5.2 (CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 5.2 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
- Vendor
- U-Boot
- Product
- U-Boot
- Reported
- 2026-07-28
- Disclosure
- 2026-09-29
- Affected
- U-Boot before 2026.10-rc4
- Fixed in
- 2026.10-rc4 (commit 561ae28cb56a082cfa90c1c421c4955bc215470b)
Executive Summary
U-Boot can parse a SquashFS image from storage during boot, for example to load a kernel, before that image is verified. The allocation size for the SquashFS directory table is computed from an attacker-controlled header field and can overflow, so the buffer is under-allocated and later writes run past its end. A crafted SquashFS image therefore corrupts heap memory inside the bootloader.
Affected Products and Versions
- Product: U-Boot, SquashFS directory table handling in
fs/squashfs/sqfs.c(sqfs_read_directory_table()). - Affected: U-Boot before 2026.10-rc4.
- Fixed: 2026.10-rc4 and later.
Technical Details
sqfs_read_directory_table() computes the size of the directory-table buffer
from the superblock's attacker-controlled metablks_count value. The
computation can overflow, so the allocation is smaller than the data that is
subsequently written into it, producing heap buffer under-allocation and
out-of-bounds writes when a crafted SquashFS image is parsed.
Reachability and Preconditions
- U-Boot parses a SquashFS image during boot (for example to load a kernel) from storage the attacker can supply, before that artifact is verified.
Impact
Heap buffer under-allocation and out-of-bounds writes that corrupt heap memory and crash the bootloader. Because the parse runs inside U-Boot, the verified-boot enforcer, before the artifact is verified, the corruption can lead to a secure-boot bypass.
Remediation and Mitigation
Update U-Boot to 2026.10-rc4 or later, which contains commit
561ae28cb56a082cfa90c1c421c4955bc215470b. Where possible, avoid parsing
SquashFS images from untrusted storage before verification until the fix is
deployed.
Timeline
- 2026-07-28 — Vulnerability public and fix available upstream.
- 2026.10-rc4 — Fix released (commit
561ae28cb56a082cfa90c1c421c4955bc215470b). - 2026-09-29 — CVE-2026-71973 record published by VulnCheck.
Credits
Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.