Skip to finding
important · Boot chain — firmware

Fragmented IP traffic can redirect execution inside U-Boot before the operating system starts.

Affects

Das U-Boot, an embedded bootloader used by network appliances and other devices, when built with CONFIG_IP_DEFRAG=y.

Exposure requires adjacent traffic during use of a CONFIG_IP_DEFRAG-enabled U-Boot network stack.

Detail and 2 sources

A duplicated final fragment reaches stale reassembly state, turns payload bytes into hole metadata and drives out-of-bounds writes that redirect control flow into attacker-supplied pkt_buff data.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026