U-Boot — Buffer Overflow via NFS READ Reply Length
U-Boot's NFS client stores the server-supplied READ length in a signed integer and bounds it with a pointer-difference check that a negative length passes, then copies it as an unsigned length, so a malicious NFS server can drive an approximately 2 GB out-of-bounds write.
- Advisory
- BYTERAY-2026-0216
- CVE
- CVE-2026-74220
- CWE
- CWE-195
- CVSS
- 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
- Vendor
- U-Boot
- Product
- U-Boot
- Reported
- 2026-08-19
- Disclosure
- 2026-09-29
- Affected
- U-Boot before 2026.10-rc5
- Fixed in
- 2026.10-rc5 (commit 0bbf09859658b8cc9ac13be41af23b516b8ef69a)
Executive Summary
When U-Boot boots over NFS, the NFS server supplies the length of each READ reply. U-Boot stores that length in a signed integer and validates it with a pointer-difference comparison that a value with the top bit set passes, then uses the same length as an unsigned size in the copy. A malicious NFS server, or an on-path attacker, can therefore turn a single reply into an out-of-bounds write of roughly 2 GB.
Affected Products and Versions
- Product: U-Boot, NFS client in
net/nfs-common.c(nfs_read_reply(), viastore_block()). Both the classic and the lwIP NFS clients reach this throughnfs_pkt_recv(). - Affected: U-Boot before 2026.10-rc5.
- Fixed: 2026.10-rc5 and later.
Technical Details
nfs_read_reply() stores the server-supplied read length in a signed int and
bounds it with a pointer-difference comparison. On an LP64 target that difference
is a 64-bit ptrdiff_t, so a length with the top bit set is negative, the sum
stays negative, and the check passes. store_block() then takes the length as an
unsigned int, so 0x80000000 becomes an approximately 2 GB memcpy() that
reads past the 1152-byte rpc_pkt stack buffer and writes past
image_load_addr.
A large positive length is also unsafe: the existing check bounds it by the
packet length rather than the reply buffer, so on the NFSv3 path a length up to
about 1128 still reads past the end of rpc_pkt.
Reachability and Preconditions
- The device boots from, or mounts, an NFS server, and the attacker controls that server or is on the network path (MITM).
- No authentication is required beyond serving the NFS reply. Both the classic and the lwIP NFS clients are affected.
Impact
An out-of-bounds read of the stack reply buffer and an out-of-bounds write past the load buffer, corrupting memory and crashing the bootloader. The write is large and attacker-influenced, so it is a plausible path to code execution in the bootloader.
Remediation and Mitigation
Update U-Boot to 2026.10-rc5 or later, which contains commit
0bbf09859658b8cc9ac13be41af23b516b8ef69a. Where possible, boot only from
trusted NFS servers over trusted network paths until the fix is deployed.
Timeline
- 2026-08-19 — Vulnerability public and fix available upstream.
- 2026.10-rc5 — Fix released (commit
0bbf09859658b8cc9ac13be41af23b516b8ef69a). - 2026-09-29 — CVE-2026-74220 record published by VulnCheck.
Credits
Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.