U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a netw
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H약점 (CWE)
상세 설명
U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- denx u-boot< 2026.04other
- denx u-bootother
- denx u-bootother
- denx u-bootother
영향받는 구성 (CPE) 4
- denx u-boot< 2026.04cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
- denx u-boot 2026.04cpe:2.3:a:denx:u-boot:2026.04:rc1:*:*:*:*:*:*
- denx u-boot 2026.04cpe:2.3:a:denx:u-boot:2026.04:rc2:*:*:*:*:*:*
- denx u-boot 2026.04cpe:2.3:a:denx:u-boot:2026.04:rc3:*:*:*:*:*:*
참고 자료 4
- https://lists.denx.de/pipermail/u-boot/2026-May/617853.htmlMailing ListThird Party Advisory
- https://u-boot.org/Product
- https://www.vulncheck.com/advisories/u-boot-rc3-integer-underflow-dos-via-tcp-rx-state-machineThird Party AdvisoryExploit
- https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/Third Party AdvisoryExploit
링크 내용 불러오는 중…