← ALL ADVISORIES

HIGH BYTERAY-2026-0218Disclosed

U-Boot — Use-After-Free in the lwIP wget Receive Callback

On a storage failure U-Boot's lwIP wget receive callback aborts and frees the TCP connection but returns the wrong status code, so the lwIP TCP input path keeps using the freed connection object, a use-after-free reachable from a malicious HTTP server.

Advisory
BYTERAY-2026-0218
CVE
CVE-2026-74222
CWE
CWE-416
CVSS
8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Vendor
U-Boot
Product
U-Boot
Reported
2026-09-01
Disclosure
2026-09-29
Affected
U-Boot before 2026.10-rc5
Fixed in
2026.10-rc5 (commit 2d94618a58aeb7630f18eee33419ce48d0fd3616)

Executive Summary

When U-Boot fetches a boot image over HTTP with the lwIP-based wget, the receive callback frees the TCP connection if it cannot store the received data, but returns the wrong status code afterwards. lwIP's contract requires a callback that aborts to signal that it aborted; because it does not, the TCP input path keeps using the connection object that was just freed. A malicious HTTP server that returns more data than the wget buffer holds triggers this path.

Affected Products and Versions

  • Product: U-Boot, lwIP wget client in net/lwip/wget.c (httpc_recv_cb()).
  • Affected: U-Boot before 2026.10-rc5.
  • Fixed: 2026.10-rc5 and later.

Technical Details

On a store_block() failure (the download buffer is smaller than the body a server sends) httpc_recv_cb() calls altcp_abort(), which frees the pcb immediately, but returns ERR_BUF instead of ERR_ABRT. lwIP's contract requires a callback that aborts to return ERR_ABRT; otherwise tcp_input() skips its goto aborted and keeps using the freed pcb, writing pcb->refused_data and calling tcp_output(pcb). A server that returns more data than the wget buffer holds triggers the abort path, so the freed pcb is the one tcp_input() is currently processing.

Reachability and Preconditions

  • The device fetches a boot image over HTTP with the lwIP wget, from a server the attacker controls or is on the path of.
  • The server returns a body larger than the wget download buffer, which triggers the storage failure and the abort path.

Impact

A use-after-free of the freed pcb that causes the TCP input path to access released memory and crash the bootloader. Exploitation beyond a crash depends on the freed pcb being reused between the free and the subsequent use in tcp_input().

Remediation and Mitigation

Update U-Boot to 2026.10-rc5 or later, which contains commit 2d94618a58aeb7630f18eee33419ce48d0fd3616. Where possible, fetch boot images only from trusted HTTP servers over trusted network paths until the fix is deployed.

Timeline

  • 2026-09-01 — Vulnerability public and fix available upstream.
  • 2026.10-rc5 — Fix released (commit 2d94618a58aeb7630f18eee33419ce48d0fd3616).
  • 2026-09-29 — CVE-2026-74222 record published by VulnCheck.

Credits

Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.

References