U-Boot — Use-After-Free in the lwIP wget Receive Callback
On a storage failure U-Boot's lwIP wget receive callback aborts and frees the TCP connection but returns the wrong status code, so the lwIP TCP input path keeps using the freed connection object, a use-after-free reachable from a malicious HTTP server.
- Advisory
- BYTERAY-2026-0218
- CVE
- CVE-2026-74222
- CWE
- CWE-416
- CVSS
- 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
- Vendor
- U-Boot
- Product
- U-Boot
- Reported
- 2026-09-01
- Disclosure
- 2026-09-29
- Affected
- U-Boot before 2026.10-rc5
- Fixed in
- 2026.10-rc5 (commit 2d94618a58aeb7630f18eee33419ce48d0fd3616)
Executive Summary
When U-Boot fetches a boot image over HTTP with the lwIP-based wget, the receive callback frees the TCP connection if it cannot store the received data, but returns the wrong status code afterwards. lwIP's contract requires a callback that aborts to signal that it aborted; because it does not, the TCP input path keeps using the connection object that was just freed. A malicious HTTP server that returns more data than the wget buffer holds triggers this path.
Affected Products and Versions
- Product: U-Boot, lwIP wget client in
net/lwip/wget.c(httpc_recv_cb()). - Affected: U-Boot before 2026.10-rc5.
- Fixed: 2026.10-rc5 and later.
Technical Details
On a store_block() failure (the download buffer is smaller than the body a
server sends) httpc_recv_cb() calls altcp_abort(), which frees the pcb
immediately, but returns ERR_BUF instead of ERR_ABRT. lwIP's contract
requires a callback that aborts to return ERR_ABRT; otherwise tcp_input()
skips its goto aborted and keeps using the freed pcb, writing
pcb->refused_data and calling tcp_output(pcb). A server that returns more
data than the wget buffer holds triggers the abort path, so the freed pcb is the
one tcp_input() is currently processing.
Reachability and Preconditions
- The device fetches a boot image over HTTP with the lwIP wget, from a server the attacker controls or is on the path of.
- The server returns a body larger than the wget download buffer, which triggers the storage failure and the abort path.
Impact
A use-after-free of the freed pcb that causes the TCP input path to
access released memory and crash the bootloader. Exploitation beyond a crash
depends on the freed pcb being reused between the free and the subsequent use in
tcp_input().
Remediation and Mitigation
Update U-Boot to 2026.10-rc5 or later, which contains commit
2d94618a58aeb7630f18eee33419ce48d0fd3616. Where possible, fetch boot images
only from trusted HTTP servers over trusted network paths until the fix is
deployed.
Timeline
- 2026-09-01 — Vulnerability public and fix available upstream.
- 2026.10-rc5 — Fix released (commit
2d94618a58aeb7630f18eee33419ce48d0fd3616). - 2026-09-29 — CVE-2026-74222 record published by VulnCheck.
Credits
Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.