Logo
vulnerabilityCVE-2026-34155
Name
CVE-2026-34155
Source
NVD ( link)Debian ( link)
Description
RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only the first few bytes of the payload. Given such a bundle with a legitimate signature, an attacker can modify the part of the payload which is not covered by the signature. This issue has been patched in version 1.15.2.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
rauc
Patched
systemd
Patched

Vulnerability Ratings#


7.2
CVSSv4
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
1.15.2
Not Affected
buildroot
master
258.7
Not Affected
yocto
kirkstone
250.14
Not Affected
yocto
master
259.5
Not Affected
yocto
scarthgap
255.21
Not Affected

Resolved with patches#


rauc (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix CVE-2026-34155
Titouan Christophe <titouan.christophe@mind.be>
CVE-2026-34155

systemd (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix CVE-2026-40226
Titouan Christophe <titouan.christophe@mind.be>
CVE-2026-34155