← ALL ADVISORIES

HIGH BYTERAY-2026-0219Disclosed

U-Boot — Out-of-Bounds Write via DHCPv6 DUID Option Lengths

U-Boot's DHCPv6 client takes the SERVERID and CLIENTID option lengths from a received packet without validation, so an on-link attacker answering the client's SOLICIT can overrun the transmit buffer with the saved server DUID and read past the client DUID buffer.

Advisory
BYTERAY-2026-0219
CVE
CVE-2026-74225
CWE
CWE-787
CVSS
7.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Vendor
U-Boot
Product
U-Boot
Reported
2026-08-06
Disclosure
2026-09-29
Affected
U-Boot before 2026.10-rc5
Fixed in
2026.10-rc5 (commit 20209a62bc8565fc1e040882bc03c71ff0d73076)

Executive Summary

During a DHCPv6 netboot, U-Boot reads the SERVERID and CLIENTID option lengths from the server's reply without validating them. It later copies the saved server identifier into a fixed transmit buffer using the unchecked SERVERID length, and compares the client identifier using the unchecked CLIENTID length. An attacker on the local link who answers the client's SOLICIT can therefore overrun the transmit buffer and read past the client identifier buffer.

Affected Products and Versions

  • Product: U-Boot, DHCPv6 client in net/dhcpv6.c (dhcp6_parse_options() and dhcp6_send_request_packet()).
  • Affected: U-Boot before 2026.10-rc5.
  • Fixed: 2026.10-rc5 and later.

Technical Details

dhcp6_parse_options() takes the SERVERID and CLIENTID option lengths from a received ADVERTISE or REPLY unchecked. The SERVERID length is stored as server_uid_size, and dhcp6_send_request_packet() later copies that many bytes of the saved server DUID into the fixed net_tx_packet buffer with no capacity check, so an over-long SERVERID overruns net_tx_packet, an out-of-bounds write. The CLIENTID length is passed straight to memcmp() against the fixed-size sm_params.duid buffer, so a length larger than that buffer reads past its end, an out-of-bounds read.

Reachability and Preconditions

  • The device performs a DHCPv6 netboot.
  • Any host on the local link able to answer the client's SOLICIT can supply the crafted options; the IA_ID it must match is observable in the SOLICIT.

Impact

An out-of-bounds write into net_tx_packet and an out-of-bounds read past the client DUID buffer, corrupting memory and crashing the bootloader. The write is attacker-influenced, so it is a plausible path to code execution in the bootloader. Reachability is limited to the local link.

Remediation and Mitigation

Update U-Boot to 2026.10-rc5 or later, which contains commit 20209a62bc8565fc1e040882bc03c71ff0d73076. Where possible, restrict DHCPv6 netboot to trusted links until the fix is deployed.

Timeline

  • 2026-08-06 — Vulnerability public and fix available upstream.
  • 2026.10-rc5 — Fix released (commit 20209a62bc8565fc1e040882bc03c71ff0d73076).
  • 2026-09-29 — CVE-2026-74225 record published by VulnCheck.

Credits

Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.

References