U-Boot — Out-of-Bounds Write via Android Bootmeth Partition Read
The Android bootmeth read size is taken from the untrusted boot-image header and is not bounded by the partition size, so a crafted image with an oversized header makes the block read overrun the load buffer on devices where Android Verified Boot does not gate the read.
- Advisory
- BYTERAY-2026-0215
- CVE
- CVE-2026-71974
- CWE
- CWE-787
- CVSS
- 4.3 (CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 4.8 (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H)
- Vendor
- U-Boot
- Product
- U-Boot
- Reported
- 2026-07-29
- Disclosure
- 2026-09-29
- Affected
- U-Boot before 2026.10-rc3
- Fixed in
- 2026.10-rc3 (commit 35432ef6fe2c79ab72709966e64815a45eb55c76)
Executive Summary
When U-Boot boots an Android image, it reads the boot or vendor_boot image from a partition using a size taken from the image's own header. That size is not bounded by the partition size, so a header claiming a size larger than the partition makes the read overrun the load buffer. This is reachable on devices where Android Verified Boot (AVB) does not gate the read, that is, where AVB is disabled or the device is unlocked.
Affected Products and Versions
- Product: U-Boot, Android bootmeth in
boot/bootmeth_android.c(read_slotted_partition()). - Affected: U-Boot before 2026.10-rc3.
- Fixed: 2026.10-rc3 and later.
Technical Details
read_slotted_partition() reads the boot/vendor_boot image using a size taken
from the untrusted Android boot-image header, and does not validate that size
against the partition bounds. A header that claims a size larger than the
partition makes the block read overrun the destination load buffer, writing past
its end into bootloader memory.
Reachability and Preconditions
- The device boots an Android image from media the attacker can supply, which in practice requires physical access to the media.
- The device does not gate the read with AVB: AVB is disabled, or the device is unlocked. Where verified boot is enforced, AVB gates the read.
Impact
An out-of-bounds write past the load buffer into bootloader memory, which can corrupt memory and crash the bootloader. The impact is bounded by the AVB precondition; on devices that enforce verified boot the path is gated.
Remediation and Mitigation
Update U-Boot to 2026.10-rc3 or later, which contains commit
35432ef6fe2c79ab72709966e64815a45eb55c76. Keep Android Verified Boot enabled
and the device locked, which gates the vulnerable read.
Timeline
- 2026-07-29 — Vulnerability public and fix available upstream.
- 2026.10-rc3 — Fix released (commit
35432ef6fe2c79ab72709966e64815a45eb55c76). - 2026-09-29 — CVE-2026-71974 record published by VulnCheck.
Credits
Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.