On Mon, Jul 20, 2026 at 02:43:09PM -0300, Quarkslab Vulnerability Reports wrote: > Dear u-boot developers, > > > I am contacting you on behalf of a security researcher at Quarkslab to > report vulnerabilities in u-boot as indicated in your web page > > https://docs.u-boot-project.org/en/latest/develop/security.html > > We have identified 19 vulnerabilities, mostly in networking code, with > impact ranging from DoS and information leaks to unauthenticated remote code > execution. > > Who should we report this to?
The mailing list, and the relevant maintainers for a given file, as shown by scripts/get_maintainers.pl. And please note that reports should be verified and proposed fixes (see https://docs.u-boot-project.org/en/latest/develop/sending_patches.html is just as important if not more-so than just reporting an issue. Thanks. -- Tom
signature.asc
Description: PGP signature
