U-Boot — Out-of-Bounds Write via DHCPv6 DUID Option Lengths
U-Boot's DHCPv6 client takes the SERVERID and CLIENTID option lengths from a received packet without validation, so an on-link attacker answering the client's SOLICIT can overrun the transmit buffer with the saved server DUID and read past the client DUID buffer.
- Advisory
- BYTERAY-2026-0219
- CVE
- CVE-2026-74225
- CWE
- CWE-787
- CVSS
- 7.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
- Vendor
- U-Boot
- Product
- U-Boot
- Reported
- 2026-08-06
- Disclosure
- 2026-09-29
- Affected
- U-Boot before 2026.10-rc5
- Fixed in
- 2026.10-rc5 (commit 20209a62bc8565fc1e040882bc03c71ff0d73076)
Executive Summary
During a DHCPv6 netboot, U-Boot reads the SERVERID and CLIENTID option lengths from the server's reply without validating them. It later copies the saved server identifier into a fixed transmit buffer using the unchecked SERVERID length, and compares the client identifier using the unchecked CLIENTID length. An attacker on the local link who answers the client's SOLICIT can therefore overrun the transmit buffer and read past the client identifier buffer.
Affected Products and Versions
- Product: U-Boot, DHCPv6 client in
net/dhcpv6.c(dhcp6_parse_options()anddhcp6_send_request_packet()). - Affected: U-Boot before 2026.10-rc5.
- Fixed: 2026.10-rc5 and later.
Technical Details
dhcp6_parse_options() takes the SERVERID and CLIENTID option lengths from a
received ADVERTISE or REPLY unchecked. The SERVERID length is stored as
server_uid_size, and dhcp6_send_request_packet() later copies that many bytes
of the saved server DUID into the fixed net_tx_packet buffer with no capacity
check, so an over-long SERVERID overruns net_tx_packet, an out-of-bounds write.
The CLIENTID length is passed straight to memcmp() against the fixed-size
sm_params.duid buffer, so a length larger than that buffer reads past its end,
an out-of-bounds read.
Reachability and Preconditions
- The device performs a DHCPv6 netboot.
- Any host on the local link able to answer the client's SOLICIT can supply the crafted options; the IA_ID it must match is observable in the SOLICIT.
Impact
An out-of-bounds write into net_tx_packet and an out-of-bounds read
past the client DUID buffer, corrupting memory and crashing the bootloader. The
write is attacker-influenced, so it is a plausible path to code execution in the
bootloader. Reachability is limited to the local link.
Remediation and Mitigation
Update U-Boot to 2026.10-rc5 or later, which contains commit
20209a62bc8565fc1e040882bc03c71ff0d73076. Where possible, restrict DHCPv6
netboot to trusted links until the fix is deployed.
Timeline
- 2026-08-06 — Vulnerability public and fix available upstream.
- 2026.10-rc5 — Fix released (commit
20209a62bc8565fc1e040882bc03c71ff0d73076). - 2026-09-29 — CVE-2026-74225 record published by VulnCheck.
Credits
Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.