Public Security Advisories
Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.
U-Boot's IP fragment reassembly writes into the reassembly buffer using attacker-controlled fragment offset and length without adequate bounds checking, so a crafted fragmented packet sent during netboot writes out of bounds and corrupts adjacent memory.
U-Boot's RLE8 bitmap decoder does not bound its writes to the framebuffer, so a crafted RLE8-compressed BMP decoded during boot writes past the end of the framebuffer and corrupts adjacent memory inside the bootloader.
A size computation for the SquashFS directory table overflows on an attacker-controlled superblock field, producing an undersized allocation and subsequent out-of-bounds writes when U-Boot parses a crafted SquashFS image during boot.
U-Boot's NFS client stores the server-supplied READ length in a signed integer and bounds it with a pointer-difference check that a negative length passes, then copies it as an unsigned length, so a malicious NFS server can drive an approximately 2 GB out-of-bounds write.
U-Boot's NFS client takes the symlink length from a READLINK reply into a signed integer with no lower-bound check, so a negative length bypasses the capacity guard and is then used as an unsigned copy size, giving a malicious NFS server an out-of-bounds write off the path buffer.
U-Boot's DHCPv6 client takes the SERVERID and CLIENTID option lengths from a received packet without validation, so an on-link attacker answering the client's SOLICIT can overrun the transmit buffer with the saved server DUID and read past the client DUID buffer.
The Android bootmeth read size is taken from the untrusted boot-image header and is not bounded by the partition size, so a crafted image with an oversized header makes the block read overrun the load buffer on devices where Android Verified Boot does not gate the read.
The lwIP MQTT client does not enforce the MQTT limit on fixed-header length, so a malicious or man-in-the-middle broker can send a run of remaining-length continuation bytes and drive an unbounded write past a 128-byte heap buffer in the client. No MQTT authentication is required, and the primitive is a plausible path to remote code execution.
// No embargoed advisories.