← Back to CVE List
CVE-2026-15390NVD
Vulnerability Summary
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
CVSS v4.0 Base Metrics — Score 9.0 (CRITICAL)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)High
Affected & Patched Versions
- DENX Software Engineering Das U-Boot >= 2009.08 and <= 2026.07
- DENX Software Engineering Das U-Boot 2026.07