Das U-Boot IP Reassembly State Leak Arbitrary Code via IP Fragments
CVE-2026-15390 Published on September 29, 2026
Out-of-bounds write in Das U-Boot
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
Vulnerability Analysis
Weakness Types
What is a Memory Corruption Vulnerability?
The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.
CVE-2026-15390 has been classified to as a Memory Corruption vulnerability or weakness.
What is an Insufficient Cleanup Vulnerability?
The software does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVE-2026-15390 has been classified to as an Insufficient Cleanup vulnerability or weakness.
Products Associated with CVE-2026-15390
stack.watch emails you whenever new vulnerabilities are published in Denx U Boot or Canonical Ubuntu Linux. Just hit a watch button to start following.
Affected Versions
DENX Software Engineering Das U-Boot:- Version 2009.08, <= 2026.07 is affected.