Public Security Advisories
Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.
U-Boot's IP fragment reassembly writes into the reassembly buffer using attacker-controlled fragment offset and length without adequate bounds checking, so a crafted fragmented packet sent during netboot writes out of bounds and corrupts adjacent memory.
U-Boot's RLE8 bitmap decoder does not bound its writes to the framebuffer, so a crafted RLE8-compressed BMP decoded during boot writes past the end of the framebuffer and corrupts adjacent memory inside the bootloader.
A size computation for the SquashFS directory table overflows on an attacker-controlled superblock field, producing an undersized allocation and subsequent out-of-bounds writes when U-Boot parses a crafted SquashFS image during boot.
U-Boot's NFS client stores the server-supplied READ length in a signed integer and bounds it with a pointer-difference check that a negative length passes, then copies it as an unsigned length, so a malicious NFS server can drive an approximately 2 GB out-of-bounds write.
U-Boot's NFS client takes the symlink length from a READLINK reply into a signed integer with no lower-bound check, so a negative length bypasses the capacity guard and is then used as an unsigned copy size, giving a malicious NFS server an out-of-bounds write off the path buffer.
On a storage failure U-Boot's lwIP wget receive callback aborts and frees the TCP connection but returns the wrong status code, so the lwIP TCP input path keeps using the freed connection object, a use-after-free reachable from a malicious HTTP server.
U-Boot's DHCPv6 client takes the SERVERID and CLIENTID option lengths from a received packet without validation, so an on-link attacker answering the client's SOLICIT can overrun the transmit buffer with the saved server DUID and read past the client DUID buffer.
The Android bootmeth read size is taken from the untrusted boot-image header and is not bounded by the partition size, so a crafted image with an oversized header makes the block read overrun the load buffer on devices where Android Verified Boot does not gate the read.
// No embargoed advisories.