Das U-Boot IP Reassembly State Leak Arbitrary Code via IP Fragments
CVE-2026-15390 Published on September 29, 2026

Out-of-bounds write in Das U-Boot
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.

NVD

Vulnerability Analysis

Attack Vector:
ADJACENT
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Types

What is a Memory Corruption Vulnerability?

The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.

CVE-2026-15390 has been classified to as a Memory Corruption vulnerability or weakness.

What is an Insufficient Cleanup Vulnerability?

The software does not properly "clean up" and remove temporary or supporting resources after they have been used.

CVE-2026-15390 has been classified to as an Insufficient Cleanup vulnerability or weakness.


Products Associated with CVE-2026-15390

stack.watch emails you whenever new vulnerabilities are published in Denx U Boot or Canonical Ubuntu Linux. Just hit a watch button to start following.

 
 

Affected Versions

DENX Software Engineering Das U-Boot: