Hi,
On 5/8/26 7:20 PM, Wade Sparks wrote:
[You don't often get email from [email protected]. Learn why this is
important at https://aka.ms/LearnAboutSenderIdentification ]
Hello U-Boot mailing list,
I’m a vulnerability analyst at VulnCheck <https://www.vulncheck.com/>, an
exploit intelligence company and research CVE Numbering Authority (CNA),
where I'm one of several folks who manage our coordinated vulnerability
disclosure (CVD) program.
An external security researcher recently reported several vulnerabilities
<https://www.vulncheck.com/advisories/report> impacting the U-Boot
codebase (discovered against release v2026.04-rc3), and VulnCheck is acting
as the intermediary and coordinator.
VulnCheck follows a 120-day disclosure policy
<https://www.vulncheck.com/vulnerability-disclosure-policy>, meaning we
afford vendors/maintainers up to 120 days from the time of receiving the
report to address the issues before publication of CVE records and
third-party advisories. For these vulnerabilities, that 120-day deadline
falls on *September 5, 2026*.
We have provisionally allocated the following CVE IDs, which have been
shared with the researcher but will remain private until public disclosure:
- *CVE-2026-29007* - Out-of-Bounds Read in TCP Options Parser
- *CVE-2026-29008* - Integer Underflow in TCP Payload Length
Unlike claimed by your own advisories (U-Boot <= 2026.04-rc3), these
aren't fixed yet. You've also linked the wrong articles from your own
website two of the three CVEs you created as a CNA (as can be seen on
NVD website).
There also are patches suggested for the two CVEs listed above in the
"external security researcher" report. It'd be reeeeeaaaaal nice if,
when reporting vulnerabilities and patches are available, someone
actually posts them to the mailing list. If none are available, please
try to motivate reporters to engage with the community and propose a fix.
- *CVE-2026-29009* - Buffer Overflow via NFS Symlink Chain
I believe this is fixed in commit d6694018eadd ("net: nfs: fix buffer
overflow in nfs_readlink_reply()"), available since v2026.07-rc2. Your
advisory and CVE also are incorrectly generated.
You have received a separate mail at [email protected] with all this
info.
Quentin