Public Security Advisories
Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.
U-Boot's IP fragment reassembly writes into the reassembly buffer using attacker-controlled fragment offset and length without adequate bounds checking, so a crafted fragmented packet sent during netboot writes out of bounds and corrupts adjacent memory.
U-Boot's NFS client stores the server-supplied READ length in a signed integer and bounds it with a pointer-difference check that a negative length passes, then copies it as an unsigned length, so a malicious NFS server can drive an approximately 2 GB out-of-bounds write.
U-Boot's NFS client takes the symlink length from a READLINK reply into a signed integer with no lower-bound check, so a negative length bypasses the capacity guard and is then used as an unsigned copy size, giving a malicious NFS server an out-of-bounds write off the path buffer.
U-Boot's DHCPv6 client takes the SERVERID and CLIENTID option lengths from a received packet without validation, so an on-link attacker answering the client's SOLICIT can overrun the transmit buffer with the saved server DUID and read past the client DUID buffer.
// No embargoed advisories.