Hi Wade,
On 7/24/26 7:37 PM, Wade Sparks wrote:
You don't often get email from [email protected]. Learn why this is
important<https://aka.ms/LearnAboutSenderIdentification>
Hello Quentin,
Thanks for reaching out.
For some context, the vulnerabilities were originally privately disclosed to
the U-Boot maintainers where VulnCheck was then requested to disclose to the
public mailing list:
https://lists.denx.de/pipermail/u-boot/2026-May/617853.html.
I don't see how anything I've said in the previous mail would have been
impacted by a private disclosure, so not sure what this added context is
helping with?
U-Boot <= 2026.04-rc3 was the release last tested by the external researcher
that discovered the vulnerabilities.
Yes, but the wording is poor. The result is that this misleads users
into thinking they are not impacted by the CVE if they have a U-Boot >
2026.04-rc3.
The description on your website says "U-Boot through 2026.04-rc3" which
implies it's been fixed since. Something that NVD seems to agree with
since they also list this is applicable only before 2026.04-rc3, c.f.
https://nvd.nist.gov/vuln/detail/CVE-2026-29007,
https://nvd.nist.gov/vuln/detail/CVE-2026-29008 and
https://nvd.nist.gov/vuln/detail/CVE-2026-29009.
Thanks for letting us know that CVE-2026-29009 was addressed in commit d669401
- the CVE record and VC advisory have been updated.
Well, I don't know. It's just that the suggested change in the report
has been implemented in that commit. The report smells like it was at
least partially written with/by an LLM so I wouldn't know if we should
trust the suggested changes (nor the report). I haven't checked it
actually fixes it. Just had a cursory look because my CVE checker now
complained about these CVEs (and I don't care about them for this
product since we don't have network enabled in U-Boot).
Quentin