Hi,

On 5/8/26 7:20 PM, Wade Sparks wrote:
[You don't often get email from [email protected]. Learn why this is 
important at https://aka.ms/LearnAboutSenderIdentification ]

Hello U-Boot mailing list,

I’m a vulnerability analyst at VulnCheck <https://www.vulncheck.com/>, an
exploit intelligence company and research CVE Numbering Authority (CNA),
where I'm one of several folks who manage our coordinated vulnerability
disclosure (CVD) program.

An external security researcher recently reported several vulnerabilities
<https://www.vulncheck.com/advisories/report> impacting the U-Boot
codebase (discovered against release v2026.04-rc3), and VulnCheck is acting
as the intermediary and coordinator.

VulnCheck follows a 120-day disclosure policy
<https://www.vulncheck.com/vulnerability-disclosure-policy>, meaning we
afford vendors/maintainers up to 120 days from the time of receiving the
report to address the issues before publication of CVE records and
third-party advisories. For these vulnerabilities, that 120-day deadline
falls on *September 5, 2026*.

We have provisionally allocated the following CVE IDs, which have been
shared with the researcher but will remain private until public disclosure:

    - *CVE-2026-29007* - Out-of-Bounds Read in TCP Options Parser
    - *CVE-2026-29008* - Integer Underflow in TCP Payload Length

Unlike claimed by your own advisories (U-Boot <= 2026.04-rc3), these aren't fixed yet. You've also linked the wrong articles from your own website two of the three CVEs you created as a CNA (as can be seen on NVD website).

There also are patches suggested for the two CVEs listed above in the "external security researcher" report. It'd be reeeeeaaaaal nice if, when reporting vulnerabilities and patches are available, someone actually posts them to the mailing list. If none are available, please try to motivate reporters to engage with the community and propose a fix.

    - *CVE-2026-29009* - Buffer Overflow via NFS Symlink Chain

I believe this is fixed in commit d6694018eadd ("net: nfs: fix buffer overflow in nfs_readlink_reply()"), available since v2026.07-rc2. Your advisory and CVE also are incorrectly generated.

You have received a separate mail at [email protected] with all this info.

Quentin

Reply via email to