CVE-2026-29009
published 2026-07-08CVE-2026-29009: U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.56%
43.1th percentile
U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| denx | u-boot | < 2026.04 | 2026.04 |
| denx | u-boot | — | — |
| denx | u-boot | — | — |
| denx | u-boot | — | — |
| u-boot | u-boot | < 2026.07-rc2 | 2026.07-rc2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
U-Boot up to 2026.04-rc3 NFS Client net/nfs-common.c nfs_readlink_reply buffer overflow
vuldb·2026-07-12·CVSS 8.2
CVE-2026-29009 [HIGH] U-Boot up to 2026.04-rc3 NFS Client net/nfs-common.c nfs_readlink_reply buffer overflow
A vulnerability classified as very critical has been found in U-Boot up to 2026.04-rc3. The affected element is the function nfs_readlink_reply of the file net/nfs-common.c of the component NFS Client. This manipulation causes buffer overflow.
This vulnerability is handled as CVE-2026-29009. The attack can be initiated remotely. There is not any exploit available.
GHSA
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflo
ghsa_unreviewed·2026-07-08
CVE-2026-29009 [HIGH] CWE-120 U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflo
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-29009 uboot-tools: U-Boot: Memory corruption via NFS readlink buffer overflow [fedora-all]
bugzilla·2026-07-13·CVSS 8.2
CVE-2026-29009 [HIGH] CVE-2026-29009 uboot-tools: U-Boot: Memory corruption via NFS readlink buffer overflow [fedora-all]
CVE-2026-29009 uboot-tools: U-Boot: Memory corruption via NFS readlink buffer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adja
Bugzilla
CVE-2026-29009 uboot-tools: U-Boot: Memory corruption via NFS readlink buffer overflow [epel-all]
bugzilla·2026-07-13·CVSS 8.2
CVE-2026-29009 [HIGH] CVE-2026-29009 uboot-tools: U-Boot: Memory corruption via NFS readlink buffer overflow [epel-all]
CVE-2026-29009 uboot-tools: U-Boot: Memory corruption via NFS readlink buffer overflow [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjace
Bugzilla
CVE-2026-29009 u-boot: U-Boot: Memory corruption via NFS readlink buffer overflow
bugzilla·2026-07-08·CVSS 8.2
CVE-2026-29009 [HIGH] CVE-2026-29009 u-boot: U-Boot: Memory corruption via NFS readlink buffer overflow
CVE-2026-29009 u-boot: U-Boot: Memory corruption via NFS readlink buffer overflow
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
https://git.u-boot-project.org/u-boot/u-boot/-/commit/d6694018eaddefac6aae974f9cec72fd6e58f1bchttps://git.u-boot-project.org/u-boot/u-boot/-/releases/v2026.07-rc2https://lists.denx.de/pipermail/u-boot/2026-May/617853.htmlhttps://u-boot.org/https://www.vulncheck.com/advisories/u-boot-rc3-buffer-overflow-in-nfs-readlink-reply-via-nfs-readlinkhttps://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
2026-07-08
Published