Hello Quentin, Thanks for reaching out.
For some context, the vulnerabilities were originally privately disclosed to the U-Boot maintainers where VulnCheck was then requested to disclose to the public mailing list: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html. U-Boot <= 2026.04-rc3 was the release last tested by the external researcher that discovered the vulnerabilities. Thanks for letting us know that CVE-2026-29009 was addressed in commit d669401 - the CVE record and VC advisory have been updated. Best, <https://www.vulncheck.com/> Wade Sparks III VulnCheck Senior Vulnerability Analyst On Fri, Jul 24, 2026 at 12:58 PM Quentin Schulz <[email protected]> wrote: > Hi, > > On 5/8/26 7:20 PM, Wade Sparks wrote: > > [You don't often get email from [email protected]. Learn why this > is important at https://aka.ms/LearnAboutSenderIdentification ] > > > > Hello U-Boot mailing list, > > > > I’m a vulnerability analyst at VulnCheck <https://www.vulncheck.com/>, > an > > exploit intelligence company and research CVE Numbering Authority (CNA), > > where I'm one of several folks who manage our coordinated vulnerability > > disclosure (CVD) program. > > > > An external security researcher recently reported several vulnerabilities > > <https://www.vulncheck.com/advisories/report> impacting the U-Boot > > codebase (discovered against release v2026.04-rc3), and VulnCheck is > acting > > as the intermediary and coordinator. > > > > VulnCheck follows a 120-day disclosure policy > > <https://www.vulncheck.com/vulnerability-disclosure-policy>, meaning we > > afford vendors/maintainers up to 120 days from the time of receiving the > > report to address the issues before publication of CVE records and > > third-party advisories. For these vulnerabilities, that 120-day deadline > > falls on *September 5, 2026*. > > > > We have provisionally allocated the following CVE IDs, which have been > > shared with the researcher but will remain private until public > disclosure: > > > > - *CVE-2026-29007* - Out-of-Bounds Read in TCP Options Parser > > - *CVE-2026-29008* - Integer Underflow in TCP Payload Length > > Unlike claimed by your own advisories (U-Boot <= 2026.04-rc3), these > aren't fixed yet. You've also linked the wrong articles from your own > website two of the three CVEs you created as a CNA (as can be seen on > NVD website). > > There also are patches suggested for the two CVEs listed above in the > "external security researcher" report. It'd be reeeeeaaaaal nice if, > when reporting vulnerabilities and patches are available, someone > actually posts them to the mailing list. If none are available, please > try to motivate reporters to engage with the community and propose a fix. > > > - *CVE-2026-29009* - Buffer Overflow via NFS Symlink Chain > > I believe this is fixed in commit d6694018eadd ("net: nfs: fix buffer > overflow in nfs_readlink_reply()"), available since v2026.07-rc2. Your > advisory and CVE also are incorrectly generated. > > You have received a separate mail at [email protected] with all this > info. > > Quentin >
