Vulnerability Description
U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Denx | U-Boot | < 2026.04 |
Related Weaknesses (CWE)
References
- https://lists.denx.de/pipermail/u-boot/2026-May/617853.htmlMailing ListThird Party Advisory
- https://u-boot.org/Product
- https://www.vulncheck.com/advisories/u-boot-rc3-integer-underflow-dos-via-tcp-rxThird Party AdvisoryExploit
- https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/Third Party AdvisoryExploit
FAQ
What is CVE-2026-29008?
CVE-2026-29008 is a vulnerability with a CVSS score of 7.5 (HIGH). U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a m...
How severe is CVE-2026-29008?
CVE-2026-29008 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29008?
Check the references section above for vendor advisories and patch information. Affected products include: Denx U-Boot.