← ALL ADVISORIES

HIGH BYTERAY-2026-0216Disclosed

U-Boot — Buffer Overflow via NFS READ Reply Length

U-Boot's NFS client stores the server-supplied READ length in a signed integer and bounds it with a pointer-difference check that a negative length passes, then copies it as an unsigned length, so a malicious NFS server can drive an approximately 2 GB out-of-bounds write.

Advisory
BYTERAY-2026-0216
CVE
CVE-2026-74220
CWE
CWE-195
CVSS
8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Vendor
U-Boot
Product
U-Boot
Reported
2026-08-19
Disclosure
2026-09-29
Affected
U-Boot before 2026.10-rc5
Fixed in
2026.10-rc5 (commit 0bbf09859658b8cc9ac13be41af23b516b8ef69a)

Executive Summary

When U-Boot boots over NFS, the NFS server supplies the length of each READ reply. U-Boot stores that length in a signed integer and validates it with a pointer-difference comparison that a value with the top bit set passes, then uses the same length as an unsigned size in the copy. A malicious NFS server, or an on-path attacker, can therefore turn a single reply into an out-of-bounds write of roughly 2 GB.

Affected Products and Versions

  • Product: U-Boot, NFS client in net/nfs-common.c (nfs_read_reply(), via store_block()). Both the classic and the lwIP NFS clients reach this through nfs_pkt_recv().
  • Affected: U-Boot before 2026.10-rc5.
  • Fixed: 2026.10-rc5 and later.

Technical Details

nfs_read_reply() stores the server-supplied read length in a signed int and bounds it with a pointer-difference comparison. On an LP64 target that difference is a 64-bit ptrdiff_t, so a length with the top bit set is negative, the sum stays negative, and the check passes. store_block() then takes the length as an unsigned int, so 0x80000000 becomes an approximately 2 GB memcpy() that reads past the 1152-byte rpc_pkt stack buffer and writes past image_load_addr.

A large positive length is also unsafe: the existing check bounds it by the packet length rather than the reply buffer, so on the NFSv3 path a length up to about 1128 still reads past the end of rpc_pkt.

Reachability and Preconditions

  • The device boots from, or mounts, an NFS server, and the attacker controls that server or is on the network path (MITM).
  • No authentication is required beyond serving the NFS reply. Both the classic and the lwIP NFS clients are affected.

Impact

An out-of-bounds read of the stack reply buffer and an out-of-bounds write past the load buffer, corrupting memory and crashing the bootloader. The write is large and attacker-influenced, so it is a plausible path to code execution in the bootloader.

Remediation and Mitigation

Update U-Boot to 2026.10-rc5 or later, which contains commit 0bbf09859658b8cc9ac13be41af23b516b8ef69a. Where possible, boot only from trusted NFS servers over trusted network paths until the fix is deployed.

Timeline

  • 2026-08-19 — Vulnerability public and fix available upstream.
  • 2026.10-rc5 — Fix released (commit 0bbf09859658b8cc9ac13be41af23b516b8ef69a).
  • 2026-09-29 — CVE-2026-74220 record published by VulnCheck.

Credits

Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.

References