← ALL ADVISORIES

HIGH BYTERAY-2026-0217Disclosed

U-Boot — Buffer Overflow via NFS READLINK Reply Length

U-Boot's NFS client takes the symlink length from a READLINK reply into a signed integer with no lower-bound check, so a negative length bypasses the capacity guard and is then used as an unsigned copy size, giving a malicious NFS server an out-of-bounds write off the path buffer.

Advisory
BYTERAY-2026-0217
CVE
CVE-2026-74221
CWE
CWE-195
CVSS
8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Vendor
U-Boot
Product
U-Boot
Reported
2026-08-19
Disclosure
2026-09-29
Affected
U-Boot before 2026.10-rc5
Fixed in
2026.10-rc5 (commit 1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd)

Executive Summary

When U-Boot resolves a symbolic link over NFS, the NFS server supplies the symlink length in the READLINK reply. U-Boot reads it into a signed integer with no lower-bound check, so a negative length slips through the capacity guard and is then used as an unsigned size in the copy. A malicious NFS server can move the client into the readlink state and return such a reply to overrun the path buffer.

Affected Products and Versions

  • Product: U-Boot, NFS client in net/nfs-common.c (nfs_readlink_reply()).
  • Affected: U-Boot before 2026.10-rc5.
  • Fixed: 2026.10-rc5 and later.

Technical Details

nfs_readlink_reply() takes the symlink length from the server reply into a signed int with no lower-bound check. In the relative-symlink branch the guard is pathlen + rlen >= sizeof(nfs_path_buff); a length of -1 makes this pathlen - 1, a small positive value that slips through, and rlen is then used as an unsigned size_t in memcpy(), so the copy runs off nfs_path_buff, a catastrophic out-of-bounds write.

Separately, the length is measured from the reply header rather than from the symlink data, which begins a few words later, so a large positive length reads a few bytes past the received reply, an out-of-bounds read.

Reachability and Preconditions

  • The device boots from, or mounts, an NFS server, and the attacker controls that server or is on the network path (MITM).
  • The server reaches this handler by answering the client's read with an ISDIR status to move it into the readlink state, then returning the crafted reply.

Impact

An out-of-bounds read past the received reply and a catastrophic out-of-bounds write off nfs_path_buff, corrupting memory and crashing the bootloader. The write is attacker-influenced, so it is a plausible path to code execution in the bootloader.

Remediation and Mitigation

Update U-Boot to 2026.10-rc5 or later, which contains commit 1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd. Where possible, boot only from trusted NFS servers over trusted network paths until the fix is deployed.

Timeline

  • 2026-08-19 — Vulnerability public and fix available upstream.
  • 2026.10-rc5 — Fix released (commit 1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd).
  • 2026-09-29 — CVE-2026-74221 record published by VulnCheck.

Credits

Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.

References