Hello Quentin,

Thanks for reaching out.

For some context, the vulnerabilities were originally privately disclosed
to the U-Boot maintainers where VulnCheck was then requested to disclose to
the public mailing list:
https://lists.denx.de/pipermail/u-boot/2026-May/617853.html.

U-Boot <= 2026.04-rc3 was the release last tested by the external
researcher that discovered the vulnerabilities.

Thanks for letting us know that CVE-2026-29009 was addressed in commit
d669401 - the CVE record and VC advisory have been updated.

Best,

<https://www.vulncheck.com/>

Wade Sparks III
VulnCheck
Senior Vulnerability Analyst


On Fri, Jul 24, 2026 at 12:58 PM Quentin Schulz <[email protected]>
wrote:

> Hi,
>
> On 5/8/26 7:20 PM, Wade Sparks wrote:
> > [You don't often get email from [email protected]. Learn why this
> is important at https://aka.ms/LearnAboutSenderIdentification ]
> >
> > Hello U-Boot mailing list,
> >
> > I’m a vulnerability analyst at VulnCheck <https://www.vulncheck.com/>,
> an
> > exploit intelligence company and research CVE Numbering Authority (CNA),
> > where I'm one of several folks who manage our coordinated vulnerability
> > disclosure (CVD) program.
> >
> > An external security researcher recently reported several vulnerabilities
> > <https://www.vulncheck.com/advisories/report> impacting the U-Boot
> > codebase (discovered against release v2026.04-rc3), and VulnCheck is
> acting
> > as the intermediary and coordinator.
> >
> > VulnCheck follows a 120-day disclosure policy
> > <https://www.vulncheck.com/vulnerability-disclosure-policy>, meaning we
> > afford vendors/maintainers up to 120 days from the time of receiving the
> > report to address the issues before publication of CVE records and
> > third-party advisories. For these vulnerabilities, that 120-day deadline
> > falls on *September 5, 2026*.
> >
> > We have provisionally allocated the following CVE IDs, which have been
> > shared with the researcher but will remain private until public
> disclosure:
> >
> >     - *CVE-2026-29007* - Out-of-Bounds Read in TCP Options Parser
> >     - *CVE-2026-29008* - Integer Underflow in TCP Payload Length
>
> Unlike claimed by your own advisories (U-Boot <= 2026.04-rc3), these
> aren't fixed yet. You've also linked the wrong articles from your own
> website two of the three CVEs you created as a CNA (as can be seen on
> NVD website).
>
> There also are patches suggested for the two CVEs listed above in the
> "external security researcher" report. It'd be reeeeeaaaaal nice if,
> when reporting vulnerabilities and patches are available, someone
> actually posts them to the mailing list. If none are available, please
> try to motivate reporters to engage with the community and propose a fix.
>
> >     - *CVE-2026-29009* - Buffer Overflow via NFS Symlink Chain
>
> I believe this is fixed in commit d6694018eadd ("net: nfs: fix buffer
> overflow in nfs_readlink_reply()"), available since v2026.07-rc2. Your
> advisory and CVE also are incorrectly generated.
>
> You have received a separate mail at [email protected] with all this
> info.
>
> Quentin
>

Reply via email to