On Mon, Jul 20, 2026 at 02:43:09PM -0300, Quarkslab Vulnerability Reports wrote:
> Dear u-boot developers,
> 
> 
> I am contacting you on behalf of a security researcher at Quarkslab to
> report vulnerabilities in u-boot as indicated in your web page
> 
> https://docs.u-boot-project.org/en/latest/develop/security.html
> 
> We have identified 19 vulnerabilities, mostly in networking  code, with
> impact ranging from DoS and information leaks to unauthenticated remote code
> execution.
> 
> Who should we report this to?

The mailing list, and the relevant maintainers for a given file, as
shown by scripts/get_maintainers.pl. And please note that reports should
be verified and proposed fixes (see
https://docs.u-boot-project.org/en/latest/develop/sending_patches.html
is just as important if not more-so than just reporting an issue.
Thanks.

-- 
Tom

Attachment: signature.asc
Description: PGP signature

Reply via email to