U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enable
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L약점 (CWE)
- CWE-125
경계 밖 읽기 — 버퍼 범위를 벗어난 메모리를 읽어 민감 정보 유출·충돌 유발.
상세 설명
U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- denx u-boot< 2026.04other
- denx u-bootother
- denx u-bootother
- denx u-bootother
영향받는 구성 (CPE) 4
- denx u-boot< 2026.04cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
- denx u-boot 2026.04cpe:2.3:a:denx:u-boot:2026.04:rc1:*:*:*:*:*:*
- denx u-boot 2026.04cpe:2.3:a:denx:u-boot:2026.04:rc2:*:*:*:*:*:*
- denx u-boot 2026.04cpe:2.3:a:denx:u-boot:2026.04:rc3:*:*:*:*:*:*
참고 자료 4
- https://lists.denx.de/pipermail/u-boot/2026-May/617853.htmlMailing ListThird Party Advisory
- https://u-boot.org/Product
- https://www.vulncheck.com/advisories/u-boot-rc3-out-of-bounds-read-in-tcp-rx-state-machine-via-tcp-cThird Party AdvisoryExploit
- https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/Third Party AdvisoryExploit
링크 내용 불러오는 중…