Hi Wade,

On 7/24/26 7:37 PM, Wade Sparks wrote:
You don't often get email from [email protected]. Learn why this is 
important<https://aka.ms/LearnAboutSenderIdentification>
Hello Quentin,

Thanks for reaching out.

For some context, the vulnerabilities were originally privately disclosed to 
the U-Boot maintainers where VulnCheck was then requested to disclose to the 
public mailing list: 
https://lists.denx.de/pipermail/u-boot/2026-May/617853.html.


I don't see how anything I've said in the previous mail would have been impacted by a private disclosure, so not sure what this added context is helping with?

U-Boot <= 2026.04-rc3 was the release last tested by the external researcher 
that discovered the vulnerabilities.


Yes, but the wording is poor. The result is that this misleads users into thinking they are not impacted by the CVE if they have a U-Boot > 2026.04-rc3.

The description on your website says "U-Boot through 2026.04-rc3" which implies it's been fixed since. Something that NVD seems to agree with since they also list this is applicable only before 2026.04-rc3, c.f. https://nvd.nist.gov/vuln/detail/CVE-2026-29007, https://nvd.nist.gov/vuln/detail/CVE-2026-29008 and https://nvd.nist.gov/vuln/detail/CVE-2026-29009.

Thanks for letting us know that CVE-2026-29009 was addressed in commit d669401 
- the CVE record and VC advisory have been updated.


Well, I don't know. It's just that the suggested change in the report has been implemented in that commit. The report smells like it was at least partially written with/by an LLM so I wouldn't know if we should trust the suggested changes (nor the report). I haven't checked it actually fixes it. Just had a cursory look because my CVE checker now complained about these CVEs (and I don't care about them for this product since we don't have network enabled in U-Boot).

Quentin

Reply via email to