important · Boot chain
A crafted RLE8 splash image can write outside U-Boot’s framebuffer before the next boot stage is authenticated.
Affects
U-Boot, the bootloader used by many embedded Linux and Android devices
The attacker must place a crafted image in a configured splash-screen or PXE-menu source.
Detail and 3 sources
Repeated EOL or DELTA operations desynchronize the cursor so later pixel runs write into adjacent bootloader memory.
No public work has yet shown a verified-boot bypass or control-flow hijacking on a representative device.
Chain to watch
Place a crafted RLE8 image in a configured U-Boot splash or PXE source→↓Desynchronize the framebuffer cursor with repeated EOL or DELTA operations→↓Direct later pixel runs into adjacent bootloader memory→↓Demonstrate corruption of verification state or program control flow→↓Reliable corruption of a security-relevant object or instruction pointer on a representative device.
Unverified chainBuild a reproducer, map framebuffer-adjacent objects on representative boards, and test whether the controlled writes alter verified-boot decisions or program control flow.
Upstream published a correction, but the fix was not read for this brief.