U-Boot — Buffer Overflow via NFS READLINK Reply Length
U-Boot's NFS client takes the symlink length from a READLINK reply into a signed integer with no lower-bound check, so a negative length bypasses the capacity guard and is then used as an unsigned copy size, giving a malicious NFS server an out-of-bounds write off the path buffer.
- Advisory
- BYTERAY-2026-0217
- CVE
- CVE-2026-74221
- CWE
- CWE-195
- CVSS
- 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
- Vendor
- U-Boot
- Product
- U-Boot
- Reported
- 2026-08-19
- Disclosure
- 2026-09-29
- Affected
- U-Boot before 2026.10-rc5
- Fixed in
- 2026.10-rc5 (commit 1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd)
Executive Summary
When U-Boot resolves a symbolic link over NFS, the NFS server supplies the symlink length in the READLINK reply. U-Boot reads it into a signed integer with no lower-bound check, so a negative length slips through the capacity guard and is then used as an unsigned size in the copy. A malicious NFS server can move the client into the readlink state and return such a reply to overrun the path buffer.
Affected Products and Versions
- Product: U-Boot, NFS client in
net/nfs-common.c(nfs_readlink_reply()). - Affected: U-Boot before 2026.10-rc5.
- Fixed: 2026.10-rc5 and later.
Technical Details
nfs_readlink_reply() takes the symlink length from the server reply into a
signed int with no lower-bound check. In the relative-symlink branch the guard
is pathlen + rlen >= sizeof(nfs_path_buff); a length of -1 makes this
pathlen - 1, a small positive value that slips through, and rlen is then used
as an unsigned size_t in memcpy(), so the copy runs off nfs_path_buff, a
catastrophic out-of-bounds write.
Separately, the length is measured from the reply header rather than from the symlink data, which begins a few words later, so a large positive length reads a few bytes past the received reply, an out-of-bounds read.
Reachability and Preconditions
- The device boots from, or mounts, an NFS server, and the attacker controls that server or is on the network path (MITM).
- The server reaches this handler by answering the client's read with an ISDIR status to move it into the readlink state, then returning the crafted reply.
Impact
An out-of-bounds read past the received reply and a catastrophic
out-of-bounds write off nfs_path_buff, corrupting memory and crashing the
bootloader. The write is attacker-influenced, so it is a plausible path to code
execution in the bootloader.
Remediation and Mitigation
Update U-Boot to 2026.10-rc5 or later, which contains commit
1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd. Where possible, boot only from
trusted NFS servers over trusted network paths until the fix is deployed.
Timeline
- 2026-08-19 — Vulnerability public and fix available upstream.
- 2026.10-rc5 — Fix released (commit
1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd). - 2026-09-29 — CVE-2026-74221 record published by VulnCheck.
Credits
Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.