CVE-2026-74222

🟡 Monitoruj

W U-Boot występuje luka use-after-free, co prowadzi do awarii bootloadera.

CVSS
8.2
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the bootloader.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-09-29 22:18:33 UTC
Ostatnia modyfikacja (NVD)2026-10-02 13:17:54 UTC
Referencje